OSSA-2020-008: Open redirect in workflow forms¶
December 03, 2020
Horizon: <15.3.2, >=16.0.0 <16.2.1, >=17.0.0 <18.3.3, >=18.4.0 <18.6.0
Pritam Singh (Red Hat) reported a vulnerability in Horizon’s workflow forms. Previously there was a lack of validation on the “next” parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.
Pritam Singh from Red Hat (CVE-2020-29565)
The stable/rocky, stable/queens, and stable/pike branches are under extended maintenance and will receive no new point releases, but patches for them are provided as a courtesy.