Created attachment 1319988 [details] Screenshot Description of problem: After creating a VM creation request, the flash message shown is sent as a URL parameter, and can be easily edited, and be misused Version-Release number of selected component (if applicable): Version master.20170830023715_aa4dab9 How reproducible: 100% Steps to Reproduce: 1.Submit a request for VM creation 2.See the flash message 3. Actual results: Flash message in the URL url parameter Expected results: Additional info: See the attached screenshot
Please assess the impact of this issue and update the severity accordingly. Please refer to https://bugzilla.redhat.com/page.cgi?id=fields.html#bug_severity for a reminder on each severity's definition. If it's something like a tracker bug where it doesn't matter, please set it to Low/Low.
*** This bug has been marked as a duplicate of bug 1475303 ***