Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0157

Опубликовано: 08 апр. 2014
Источник: redhat
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3python-django-horizonWill not fix
OpenStack 4 for RHEL 6python-django-horizonFixedRHSA-2014:058129.05.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1082858openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

nvd
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

debian
почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration ...

github
больше 3 лет назад

OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting

4.3 Medium

CVSS2