PT-2014-5346 · Openstack+1 · Openstack Dashboard+1

CVE-2014-3474

·

Publicado

2014-07-09

·

Atualizado

2026-07-02

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Dashboard (Horizon) versions 2013.2.3 and earlier OpenStack Dashboard (Horizon) versions 2014.1 and earlier, excluding 2014.1.2 and later OpenStack Dashboard (Horizon) versions Juno and earlier, excluding Juno-2 and later
Description A cross-site scripting (XSS) issue exists in the Launch Instance menu, allowing remote authenticated users to inject arbitrary web script or HTML via a network name. This is due to a vulnerability in the horizon/static/horizon/js/horizon.instances.js file.
Recommendations For OpenStack Dashboard (Horizon) versions 2013.2.3 and earlier, update to version 2013.2.4 or later. For OpenStack Dashboard (Horizon) versions 2014.1 and earlier, excluding 2014.1.2 and later, update to version 2014.1.2 or later. For OpenStack Dashboard (Horizon) versions Juno and earlier, excluding Juno-2 and later, update to version Juno-2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3474
GHSA-J57P-G33W-95C5
PYSEC-2026-644
RHSA-2014:0939
RHSA-2014:1188
USN-2323-1

Produtos afetados

Openstack Dashboard
Ubuntu