Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cmg8-5c63-pg95

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.1

Описание

OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

Пакеты

Наименование

horizon

pip
Затронутые версииВерсия исправления

>= 2013.2, < 2013.2.4

2013.2.4

EPSS

Процентиль: 50%
0.00264
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

redhat
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

nvd
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

debian
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration ...

EPSS

Процентиль: 50%
0.00264
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-79