[Openstack-security] [openstack/nova] SecurityImpact review request change Icda3f8aad0e5dde0be2b12accf03f092634ecde3
gerrit2 at review.openstack.org
gerrit2 at review.openstack.org
Wed Mar 11 20:45:55 UTC 2015
Hi, I'd like you to take a look at this patch for potential
SecurityImpact.
https://review.openstack.org/163604
Log:
commit 2d422981521301516d5f2c93726ea01ec519fe2a
Author: Dave McCowan <dmccowan at cisco.com>
Date: Mon Mar 2 15:00:22 2015 -0500
Websocket Proxy should verify Origin header
If the Origin HTTP header passed in the WebSocket handshake does
not match the host, this could indicate an attempt at a
cross-site attack. This commit adds a check to verify
the origin matches the host.
SecurityImpact
Change-Id: Icda3f8aad0e5dde0be2b12accf03f092634ecde3
Closes-Bug: 1409142
More information about the Openstack-security
mailing list