PT-2015-6374 · Openstack · Nova+2
Sunil Yadav
·
Publicado
2015-05-19
·
Atualizado
2016-12-24
·
CVE-2015-3988
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Dashboard (Horizon) version 2015.1.0
Description
The issue allows remote authenticated users to inject arbitrary web script or HTML via metadata to various components, including a Glance image, Nova flavor, or Host Aggregate.
Recommendations
For OpenStack Dashboard (Horizon) version 2015.1.0, update to a version that addresses the XSS vulnerabilities to prevent remote authenticated users from injecting arbitrary web script or HTML.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Glance
Nova
Openstack Dashboard