|
|
| |
|
| |
horizon: cross-site scripting
| Package(s): | horizon |
CVE #(s): | CVE-2012-3540
|
| Created: | September 13, 2012 |
Updated: | October 24, 2012 |
| Description: |
From the Ubuntu advisory:
Thomas Biege discovered that the Horizon authentication mechanism
did not validate the next parameter. An attacker could use this to
construct a link to legitimate OpenStack web dashboard that redirected
the user to a malicious website after authentication.
|
| Alerts: |
|
( Log in to post comments)
|
|
|