oss-sec mailing list archives
CVE request for vulnerability in OpenStack Horizon
From: Tristan Cacqueray <tristan.cacqueray () enovance com>
Date: Tue, 12 May 2015 14:37:35 -0400
A vulnerability was discovered in OpenStack (see below). In order to ensure full traceability, we need a CVE number assigned that we can attach to further notifications. This issue is already public, although an advisory was not sent yet. Title: Persistent XSS in Horizon metadata dashboard Reporter: Sunil Yadav (IBM) Products: Horizon Affects: version 2015.1.0 Description: Sunil Yadav from IBM Security Services reported a persistent XSS in Horizon. An authenticated user may conduct a persistent XSS attack by setting a malicious metadata to a Glance image, a Nova flavor or a Host Aggregate and tricking an administrator to load the update metadata page. Once executed in a legitimate context this attack may result in a privilege escalation. All Horizon setups are affected. References: https://launchpad.net/bugs/1449260 Thanks in advance, -- Tristan Cacqueray OpenStack Vulnerability Management Team
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- CVE request for vulnerability in OpenStack Horizon Tristan Cacqueray (May 12)
- Re: CVE request for vulnerability in OpenStack Horizon cve-assign (May 14)