Red hat has found an open redirection vulnerability in horizon which could lead to a phishing attack, tricking users to visit malicious websites.
Upstream: https://bugs.launchpad.net/bugs/1865026
Acknowledgments: Name: Pritam Singh (Red Hat)
Upstream patch: https://git.openstack.org/cgit/openstack/horizon/commit/?id=252467100f75587e18df9c43ed5802ee8f0017fa
Created python-django-horizon tracking bugs for this issue: Affects: openstack-rdo [bug 1904883]
External References: https://www.openwall.com/lists/oss-security/2020/12/08/2
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.1 Via RHSA-2020:5411 https://access.redhat.com/errata/RHSA-2020:5411
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-29565
This issue has been addressed in the following products: Red Hat OpenStack Platform 13.0 (Queens) Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS Via RHSA-2020:5572 https://access.redhat.com/errata/RHSA-2020:5572