CVE-2012-3540
EPSS 2.9%
描述
Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter to auth/login/. NOTE: this issue was originally assigned CVE-2012-3542 by mistake.
如何修補 CVE-2012-3540
要修補 CVE-2012-3540,請將受影響套件升級到下列已修補版本。
- Debian/horizon—升級至 2012.1.1-4 或更新版本
- PyPI/horizon—升級至 35eada8a27323c0f83c400177797927aba6bc99b 或更新版本
CVE-2012-3540 正在被利用嗎?
低 — EPSS 為 2.9%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2012.1.1-4
- from 0, < 35eada8a27323c0f83c400177797927aba6bc99b | from 0