CVE-2012-2094
published 2012-06-05CVE-2012-2094: Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon)…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.42%
82.4th percentile
Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 2012.1-3 (bookworm) | horizon 2012.1-3 (bookworm) |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | >= 0 < 2012.1-3 | 2012.1-3 |
| openstack | horizon | >= 0 < 2012.1-3 | 2012.1-3 |
| openstack | horizon | >= 0 < 2012.1-3 | 2012.1-3 |
| openstack | horizon | >= 0 < 2012.1-3 | 2012.1-3 |
| openstack | horizon | >= 0 < 8.0.0a0 | 8.0.0a0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Horizon Cross-site scripting (XSS) vulnerability
osv·2022-05-17
CVE-2012-2094 [MEDIUM] OpenStack Horizon Cross-site scripting (XSS) vulnerability
OpenStack Horizon Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in `horizon/static/horizon/js/horizon.js` in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.
GHSA
OpenStack Horizon Cross-site scripting (XSS) vulnerability
ghsa·2022-05-17
CVE-2012-2094 [MEDIUM] CWE-79 OpenStack Horizon Cross-site scripting (XSS) vulnerability
OpenStack Horizon Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in `horizon/static/horizon/js/horizon.js` in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.
OSV
CVE-2012-2094: Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon
osv·2012-06-05·CVSS 4.3
CVE-2012-2094 [MEDIUM] CVE-2012-2094: Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon
Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.
Ubuntu
Horizon vulnerabilities
vendor_ubuntu·2012-05-07·CVSS 4.3
CVE-2012-2094 [MEDIUM] Horizon vulnerabilities
Title: Horizon vulnerabilities
Summary: Horizon could be made to expose sensitive information over the network.
Matthias Weckbecker discovered a cross-site scripting (XSS) vulnerability
in Horizon via the log viewer refrash mechanism. If a user were tricked
into viewing a specially crafted log message, a remote attacker could
exploit this to modify the contents or steal confidential data within the
same domain. (CVE-2012-2094)
Thomas Biege discovered a session fixation vulnerability in Horizon. An
attacker could exploit this to potentially allow access to unauthorized
information and capabilities. (CVE-2012-2144)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-2094: horizon - Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log vie...
vendor_debian·2012·CVSS 4.3
CVE-2012-2094 [MEDIUM] CVE-2012-2094: horizon - Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log vie...
Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.
Scope: local
bookworm: resolved (fixed in 2012.1-3)
bullseye: resolved (fixed in 2012.1-3)
forky: resolved (fixed in 2012.1-3)
sid: resolved (fixed in 2012.1-3)
trixie: resolved (fixed in 2012.1-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2094 python-django-horizon: XSS vulnerability in Horizon log viewer
bugzilla·2012-04-17·CVSS 4.3
CVE-2012-2094 [MEDIUM] CVE-2012-2094 python-django-horizon: XSS vulnerability in Horizon log viewer
CVE-2012-2094 python-django-horizon: XSS vulnerability in Horizon log viewer
Created attachment 578085
proposed fix
This is an advance warning of a vulnerability discovered in OpenStack,
to give you, as downstream stakeholders, a chance to coordinate the
release of fixes and reduce the vulnerability window. Please treat the
following information as confidential until the proposed public
disclosure date.
Title: XSS vulnerability in Horizon log viewer
Impact: High
Reporter: J. Daniel Schmidt
Products: Horizon
Affects: All versions
Description:
J. Daniel Schmidt reported a vulnerability in Horizon. He noted that
the log viewer refreshing mechanism does not escape the data fetched
from guest consoles. This means that HTML with Javascript code gets
interpreted as such, resulting in the abil
Bugzilla
CVE-2012-2094 python-django-horizon: XSS vulnerability in Horizon log viewer [fedora-17]
bugzilla·2012-04-17·CVSS 4.3
CVE-2012-2094 [MEDIUM] CVE-2012-2094 python-django-horizon: XSS vulnerability in Horizon log viewer [fedora-17]
CVE-2012-2094 python-django-horizon: XSS vulnerability in Horizon log viewer [fedora-17]
please see the bug #813391 for more details on this vulnerability
Discussion:
python-django-horizon-2012.1-2.fc17 has been submitted as an update for Fedora 17.
https://admin.fedoraproject.org/updates/python-django-horizon-2012.1-2.fc17
---
Package python-django-horizon-2012.1-2.fc17:
* should fix your issue,
* was pushed to the Fedora 17 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing python-django-horizon-2012.1-2.fc17'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2012-6108/python-django-horizon-2012.1-2.fc17
then log in and leave karma (f
http://lists.fedoraproject.org/pipermail/package-announce/2012-April/079160.htmlhttp://secunia.com/advisories/49024http://secunia.com/advisories/49071http://ubuntu.com/usn/usn-1439-1http://www.osvdb.org/81742https://bugs.launchpad.net/horizon/+bug/977944https://exchange.xforce.ibmcloud.com/vulnerabilities/76136https://github.com/openstack/horizon/commit/7f8c788aa70db98ac904f37fa4197fcabb802942https://lists.launchpad.net/openstack/msg10211.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-April/079160.htmlhttp://secunia.com/advisories/49024http://secunia.com/advisories/49071http://ubuntu.com/usn/usn-1439-1http://www.osvdb.org/81742https://bugs.launchpad.net/horizon/+bug/977944https://exchange.xforce.ibmcloud.com/vulnerabilities/76136https://github.com/openstack/horizon/commit/7f8c788aa70db98ac904f37fa4197fcabb802942https://lists.launchpad.net/openstack/msg10211.html
2012-06-05
Published