LWN.net Logo

horizon: cross-site scripting

Package(s):horizon CVE #(s):CVE-2012-3540
Created:September 13, 2012 Updated:October 24, 2012
Description:

From the Ubuntu advisory:

Thomas Biege discovered that the Horizon authentication mechanism did not validate the next parameter. An attacker could use this to construct a link to legitimate OpenStack web dashboard that redirected the user to a malicious website after authentication.

Alerts:
Ubuntu USN-1565-1 2012-09-12
Red Hat RHSA-2012:1380-01 2012-10-16
Fedora FEDORA-2012-16148 2012-10-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds