Cross-Site Scripting Vulnerability in OpenStack Horizon Dashboard
CVE-2014-0157

Currently unrated

Key Information:

Vendor
Openstack
Status
Vendor
CVE Published:
15 April 2014

Summary

The OpenStack Horizon dashboard is susceptible to a Cross-Site Scripting (XSS) vulnerability, which arises due to improper handling of user input in the description field of a Heat template. This flaw permits remote attackers to inject arbitrary web scripts or HTML, potentially compromising the security of the application and impacting users' privacy. Effective mitigation measures must be employed to safeguard against unauthorized script execution within the Horizon interface.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.