PT-2023-10140 · Openstack · Openstack Dashboard
Published
2023-01-08
·
Updated
2024-05-17
·
CVE-2014-125070
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
yanheven console (affected versions not specified)
Description
A vulnerability has been found in the yanheven console, classified as problematic. The issue affects the function
get zone hosts/AvailabilityZonesTable of the file openstack dashboard/dashboards/admin/aggregates/tables.py, leading to cross-site scripting. The attack can be launched remotely.Recommendations
To fix this issue, it is recommended to apply a patch named
ba908ae88d5925f4f6783eb234cc4ea95017472b. As a temporary workaround, consider disabling the get zone hosts/AvailabilityZonesTable function until a patch is available. Restrict access to the vulnerable file tables.py to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Dashboard