Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cristian Fiorentino

Researcher fromIntel
#48542of 53,633
5.1Total CVSS
Vulnerabilities · 1
PT-2014-3506
5.1
2014-04-15
Openstack · Openstack Dashboard · CVE-2014-0157
**Name of the Vulnerable Software and Affected Versions** OpenStack Dashboard (aka Horizon) versions 2013.2 before 2013.2.4 OpenStack Dashboard (aka Horizon) versions icehouse before icehouse-rc2 **Description** A cross-site scripting (XSS) issue exists in the Horizon Orchestration dashboard, allowing remote attackers to inject arbitrary web script or HTML via the `description` field of a Heat template. **Recommendations** For OpenStack Dashboard (aka Horizon) versions 2013.2 before 2013.2.4, update to version 2013.2.4 or later. For OpenStack Dashboard (aka Horizon) versions icehouse before icehouse-rc2, update to version icehouse-rc2 or later.