Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1897736

Summary: Reflected XSS vulnerability during CSRF failure
Product: Red Hat OpenStack Reporter: Nick Tait <ntait>
Component: python-django-horizonAssignee: Tatiana Ovchinnikova <tovchinn>
Status: CLOSED ERRATA QA Contact: Jan Jasek <jjasek>
Severity: high Docs Contact:
Priority: high    
Version: 16.2 (Train)CC: athomas, jjoyce, jrist, jschluet, mburns, rdopiera, slinaber, tovchinn, tvignaud
Target Milestone: z5Keywords: Reopened, Security, Triaged
Target Release: 16.2 (Train on RHEL 8.4)   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: python-django-horizon-16.2.3-2.20230227155029.d3d3d18.el8ost Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-04-26 12:16:45 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Nick Tait 2020-11-13 22:38:39 UTC
Description of problem:
Check full details in Upstream bug here https://bugs.launchpad.net/horizon/+bug/1898465

Why this is a security bug:
While it does not allow directly attacking an OpenStack deployment (and therefore no CVE will be assigned), it enables malicious people's phishing attacks to appear more legitimate by using someone else's infrastructure.

Comment 16 errata-xmlrpc 2023-04-26 12:16:45 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Red Hat OpenStack Platform 16.2.5 (Train) bug fix and enhancement advisory), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2023:1763