Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.
CVSS Details
- CVSS 3.1 Base Score: 4.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade horizon | Jul 30, 2024 | Aug 22, 2014 |
| Oracle Solaris | — | Upgrade cloud/openstack/horizon to version 0.2013.2.3-0.175.2.2.0.4.0 on Solaris 11.2 | May 29, 2017 | Aug 22, 2014 |
| Suse | — | Upgrade openstack-dashboardUpgrade python-horizon-branding-upstreamUpgrade python-django_openstack_authUpgrade openstack-dashboard-branding-upstreamUpgrade openstack-dashboard-testUpgrade python-horizon | Dec 18, 2015 | Aug 22, 2014 |
| Ubuntu | — | Upgrade openstack-dashboard | Nov 8, 2024 | Aug 22, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub