Release date:
Updated on: 2012-09-02
Affected Systems:
Openstack OpenStack Dashboard (Horizon)
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55329
Cve id: CVE-2012-3540
OpenStack Dashboard provides a basic user interface for managing OpenStack services.
OpenStack Dashboard Horizon has the free redirection vulnerability, which allows you to construct fake Uris and trick users into accessing them. Attackers can exploit this vulnerability to redirect users to malicious websites and perform phishing attacks.
<* Source: Thomas Biege (thomas@SUSE.de)
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Openstack
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://horizon.openstack.org/intro.html