Red Hat Security Advisory 2015-0790-01

Discussion in 'News Aggregator' started by Packet Storm, 9 Apr 2015.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2015-0790-01 - OpenStack Compute launches and schedules large networks of virtual machines, creating a redundant and scalable cloud computing platform. Compute provides the software, control panels, and APIs required to orchestrate a cloud, including running virtual machine instances and controlling access through users and projects. It was discovered that the OpenStack Compute console websocket did not correctly verify the origin header. An attacker could use this flaw to conduct a cross-site websocket hijack attack. Note that only Compute setups with VNC or SPICE enabled were affected by this flaw.

    Continue reading...
     

Share This Page

Loading...