PT-2014-5346 · Openstack+1 · Openstack Dashboard+1
CVE-2014-3474
·
Publicado
2014-07-09
·
Atualizado
2026-07-02
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Dashboard (Horizon) versions 2013.2.3 and earlier
OpenStack Dashboard (Horizon) versions 2014.1 and earlier, excluding 2014.1.2 and later
OpenStack Dashboard (Horizon) versions Juno and earlier, excluding Juno-2 and later
Description
A cross-site scripting (XSS) issue exists in the Launch Instance menu, allowing remote authenticated users to inject arbitrary web script or HTML via a network name. This is due to a vulnerability in the horizon/static/horizon/js/horizon.instances.js file.
Recommendations
For OpenStack Dashboard (Horizon) versions 2013.2.3 and earlier, update to version 2013.2.4 or later.
For OpenStack Dashboard (Horizon) versions 2014.1 and earlier, excluding 2014.1.2 and later, update to version 2014.1.2 or later.
For OpenStack Dashboard (Horizon) versions Juno and earlier, excluding Juno-2 and later, update to version Juno-2 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openstack Dashboard
Ubuntu