Comment 18 for bug 978896

Revision history for this message
Thierry Carrez (ttx) wrote :

Patch looks lean and clean to me. Devin, Gabriel, could you have a look and +1 it ?

@Paul: could you please review the following impact description and check that it describes the issue accurately:

"""
Title: Horizon session fixation and reuse
Impact: Critical
Reporter: Thomas Biege, SUSE
Products: Horizon
Affects: All versions

Description:
Thomas Biege from SUSE reported a vulnerability in OpenStack Dashboard (Horizon). Under specific circumstances it is possible to reuse session cookies from another user, potentially resulting in information leakage between Horizon sessions, including authentication information.
"""

Feel free to suggest corrections that would make the description more precise.