Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7400

Опубликовано: 03 мар. 2017
Источник: redhat
CVSS3: 3.5

Описание

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.

A cross-site scripting flaw was discovered in the OpenStack dashboard (horizon) which allowed remote authenticated administrators to conduct XSS attacks using a crafted federation mapping rule. For this flaw to be exploited, federation mapping must be enabled in the dashboard.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-django-horizonNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-django-horizonNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-django-horizonNot affected
Red Hat OpenStack Platform 11 (Ocata)python-django-horizonNot affected
Red Hat OpenStack Platform 8 (Liberty)python-django-horizonNot affected
Red Hat OpenStack Platform 10.0 (Newton)python-django-horizonFixedRHSA-2017:159828.06.2017
Red Hat OpenStack Platform 9.0 (Mitaka)python-django-horizonFixedRHSA-2017:173912.07.2017

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1439626python-django-horizon: XSS in federation mappings UI

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
почти 9 лет назад

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.

CVSS3: 4.8
nvd
почти 9 лет назад

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.

CVSS3: 4.8
debian
почти 9 лет назад

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 a ...

CVSS3: 4.8
github
больше 3 лет назад

OpenStack Horizon Cross-site Scripting (XSS)

3.5 Low

CVSS3