[Yahoo-eng-team] [Bug 1327425] Re: With default configuration Horizon is exposed to session-fixation attack

2014-06-23 Thread Travis McPeak
** Changed in: ossn Status: In Progress => Fix Released -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (Horizon). https://bugs.launchpad.net/bugs/1327425 Title: With default configuration Horizon is e

[Yahoo-eng-team] [Bug 1327425] Re: With default configuration Horizon is exposed to session-fixation attack

2014-06-09 Thread Thierry Carrez
Yes, I think it would make sense to issue a security note on that topic. The article by Pablo is a good read. It's a well known issue so i'll make it public. ** Information type changed from Private Security to Public ** Also affects: ossn Importance: Undecided Status: New ** Changed