OpenStack Horizon fails to validate the token provided during a SAML request allowing an attacker to forge a REFERER for redirection. Continue reading...