Cross-Site Scripting Vulnerability in OpenStack Dashboard by OpenStack
CVE-2014-3475

Currently unrated

Key Information:

Vendor
Openstack
Status
Vendor
CVE Published:
31 October 2014

Summary

A cross-site scripting (XSS) vulnerability exists in the Users panel of OpenStack Dashboard (Horizon) allowing remote administrators to inject arbitrary web scripts or HTML through user email addresses. This flaw affects various versions of Horizon prior to specific updates, creating a potential risk for administrator accounts and applications connected to the OpenStack environment.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.