CVE-2014-0157
published 2014-04-15CVE-2014-0157: Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.22%
65.1th percentile
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 2013.2.3-1 (bookworm) | horizon 2013.2.3-1 (bookworm) |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | >= 0 < 2013.2.3-1 | 2013.2.3-1 |
| openstack | horizon | >= 0 < 2013.2.3-1 | 2013.2.3-1 |
| openstack | horizon | >= 0 < 2013.2.3-1 | 2013.2.3-1 |
| openstack | horizon | >= 0 < 2013.2.3-1 | 2013.2.3-1 |
| openstack | horizon | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
osv·2022-05-14
CVE-2014-0157 [MEDIUM] OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
GHSA
OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
ghsa·2022-05-14
CVE-2014-0157 [MEDIUM] CWE-79 OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
OSV
CVE-2014-0157: Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013
osv·2014-04-15·CVSS 4.3
CVE-2014-0157 [MEDIUM] CVE-2014-0157: Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
Ubuntu
OpenStack Horizon vulnerability
vendor_ubuntu·2014-05-06
CVE-2014-0157 OpenStack Horizon vulnerability
Title: OpenStack Horizon vulnerability
Summary: OpenStack Horizon did not properly process Heat templates.
Cristian Fiorentino discovered that OpenStack Horizon did not properly
perform input sanitization for Heat templates. If a user were tricked into
using a specially crafted Heat template, an attacker could conduct
cross-site scripting attacks. With cross-site scripting vulnerabilities, if
a user were tricked into viewing server output during a crafted server
request, a remote attacker could exploit this to modify the contents, or
steal confidential data, within the same domain.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
vendor_redhat·2014-04-08·CVSS 4.3
CVE-2014-0157 [MEDIUM] CWE-79 openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
Package: python-django-horizon (Red Hat OpenStack Platform 3) - Will not fix
Debian
CVE-2014-0157: horizon - Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard ...
vendor_debian·2014·CVSS 4.3
CVE-2014-0157 [MEDIUM] CVE-2014-0157: horizon - Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard ...
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
Scope: local
bookworm: resolved (fixed in 2013.2.3-1)
bullseye: resolved (fixed in 2013.2.3-1)
forky: resolved (fixed in 2013.2.3-1)
sid: resolved (fixed in 2013.2.3-1)
trixie: resolved (fixed in 2013.2.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0157 python-django-horizon: OpenStack: XSS in Horizon orchestration dashboard when using a malicious template [fedora-all]
bugzilla·2014-04-09·CVSS 4.3
CVE-2014-0157 [MEDIUM] CVE-2014-0157 python-django-horizon: OpenStack: XSS in Horizon orchestration dashboard when using a malicious template [fedora-all]
CVE-2014-0157 python-django-horizon: OpenStack: XSS in Horizon orchestration dashboard when using a malicious template [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi no
Bugzilla
CVE-2014-0157 python-django-horizon: OpenStack: XSS in Horizon orchestration dashboard when using a malicious template [epel-6]
bugzilla·2014-04-09·CVSS 4.3
CVE-2014-0157 [MEDIUM] CVE-2014-0157 python-django-horizon: OpenStack: XSS in Horizon orchestration dashboard when using a malicious template [epel-6]
CVE-2014-0157 python-django-horizon: OpenStack: XSS in Horizon orchestration dashboard when using a malicious template [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi n
Bugzilla
CVE-2014-0157 openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
bugzilla·2014-04-01·CVSS 4.3
CVE-2014-0157 [MEDIUM] CVE-2014-0157 openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
CVE-2014-0157 openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template
It was reported that, if an Horizon user were tricked into using a malicious template in the Orchestration/Stack section of Horizon, it would be possible for an attacker to conduct cross-site scripting (XSS) attacks.
The original report notes "2013.2.1 version up to 2013.2.2" are affected.
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Cristian Fiorentino from Intel as the original reporter.
Discussion:
This issue is public now:
http://seclists.org/oss-sec/2014/q2/35
---
Created python-django-horizon tracking bugs for this issue:
Affects: fedora-all [bug 1085825]
Affects: epel-6 [bug 1085826]
---
python-djan
arXiv
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 with New Scoring and Data Sources
arxiv_fulltext·2025-08-18
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 with New Scoring and Data Sources
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 with New Scoring and Data Sources
[1,2]Tadeu Freitas
[1]Carlos Novo
[1]Inês Dutra
[1]João Soares
[1,2]Manuel E. Correia
[3]Benham Shariati
[4]Rolando Martins
FREITAS et al.
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 with New Scoring and Data Sources
[1]Department of Computer Science, Faculty of Sciences of University of Porto, Porto, Portugal
[2]Centre Advanced Computing Systems, Institute for Systems and Computer Engineering, Technology and Science, Porto, Portugal
[3]UMBC, University of Maryland, Baltimore County,Baltimore, USA
[4]SafeHelm, lda, Porto, Portugal
Corresponding author Tadeu Freitas. [email protected]
[Abstract]Intrusion Tolerant Systems (ITSs) have become increasingly
arXiv
HAL 9000: a Risk Manager for ITSs
arxiv_fulltext·2025-03-21
HAL 9000: a Risk Manager for ITSs
HAL 9000: a Risk Manager for ITSs
This work is financed by National Funds through the Portuguese funding agency, FCT - Fundação para a Ciência e a Tecnologia, within project UIDB/50014/2020.
DOI 10.54499/UIDB/50014/2020 https://doi.org/10.54499/uidb/50014/2020
This work was funded by 2021.08532.BD (FCT), and by 2021.04529.BD (FCT).
Tadeu Freitas12, Carlos Novo1, João Soares12, Inês Dutra13,
Manuel E. Correia12, Behnam Shariati4, Rolando Martins15
1Faculty of Sciences, University of Porto, Portugal
2CRACS/INESC-TEC, Portugal
3CINTESIS@RISE, Portugal
4University of Maryland, Baltimore County, USA
5SafeHelm, lda, Porto, Portugal
\tadeufreitas, joao.soares, mdcorrei, carlosnovo, ines\@fc.up.pt,
[email protected], [email protected]
## Abstract
HAL 9000 is an Intrusion Tolerant Systems
http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlhttp://www.openwall.com/lists/oss-security/2014/04/08/8http://www.securityfocus.com/bid/66706https://launchpad.net/bugs/1289033http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlhttp://www.openwall.com/lists/oss-security/2014/04/08/8http://www.securityfocus.com/bid/66706https://launchpad.net/bugs/1289033
2014-04-15
Published