CVE-2014-3474
published 2014-10-31CVE-2014-3474: Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.92%
77.6th percentile
Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 2014.1.1-3 (bookworm) | horizon 2014.1.1-3 (bookworm) |
| openstack | horizon | — | — |
| openstack | horizon | >= 0 < 2014.1.1-3 | 2014.1.1-3 |
| openstack | horizon | >= 0 < 2014.1.1-3 | 2014.1.1-3 |
| openstack | horizon | >= 0 < 2014.1.1-3 | 2014.1.1-3 |
| openstack | horizon | >= 0 < 2014.1.1-3 | 2014.1.1-3 |
| openstack | horizon | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | horizon | >= 0 < 1:2014.1.2-0ubuntu1.1 | 1:2014.1.2-0ubuntu1.1 |
| openstack | horizon | >= 2013.2 < 2013.2.4 | 2013.2.4 |
| openstack | horizon | >= 2014.1 < 2014.1.2 | 2014.1.2 |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Horizon vulnerabilities
vendor_ubuntu·2014-08-21·CVSS 4.3
CVE-2014-3473 [MEDIUM] OpenStack Horizon vulnerabilities
Title: OpenStack Horizon vulnerabilities
Summary: Several security issues were fixed in OpenStack Horizon.
Jason Hullinger discovered that OpenStack Horizon did not properly perform
input sanitization on Heat templates. If a user were tricked into using a
specially crafted Heat template, an attacker could conduct cross-site
scripting attacks. With cross-site scripting vulnerabilities, if a user
were tricked into viewing server output during a crafted server request, a
remote attacker could exploit this to modify the contents, or steal
confidential data, within the same domain. (CVE-2014-3473)
Craig Lorentzen discovered that OpenStack Horizon did not properly perform
input sanitization when creating networks. If a user were tricked into
launching an image using the crafted network name,
Red Hat
openstack-horizon: multiple XSS flaws
vendor_redhat·2014-07-08·CVSS 4.3
CVE-2014-3475 [MEDIUM] CWE-79 openstack-horizon: multiple XSS flaws
openstack-horizon: multiple XSS flaws
Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-8578.
A cross-site scripting (XSS) flaw was found in the way orchestration templates were handled. An owner of such a template could use this flaw to perform XSS attacks against other Horizon users. (CVE-2014-3473)
It was found that network names were not sanitized. A malicious user could use this flaw to perform XSS attacks against other Horizon users by creating a network with a specially-crafted name. (CVE-2014-3474)
It was found that some email a
Red Hat
openstack-horizon: multiple XSS flaws
vendor_redhat·2014-07-08·CVSS 4.3
CVE-2014-3474 [MEDIUM] CWE-79 openstack-horizon: multiple XSS flaws
openstack-horizon: multiple XSS flaws
Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name.
A cross-site scripting (XSS) flaw was found in the way orchestration templates were handled. An owner of such a template could use this flaw to perform XSS attacks against other Horizon users. (CVE-2014-3473)
It was found that network names were not sanitized. A malicious user could use this flaw to perform XSS attacks against other Horizon users by creating a network with a specially-crafted name. (CVE-2014-3474)
It was found that some email addr
Red Hat
openstack-horizon: multiple XSS flaws
vendor_redhat·2014-07-08·CVSS 4.3
CVE-2014-8578 [MEDIUM] CWE-79 openstack-horizon: multiple XSS flaws
openstack-horizon: multiple XSS flaws
Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475.
A cross-site scripting (XSS) flaw was found in the way orchestration templates were handled. An owner of such a template could use this flaw to perform XSS attacks against other Horizon users. (CVE-2014-3473)
It was found that network names were not sanitized. A malicious user could use this flaw to perform XSS attacks against other Horizon users by creating a network with a specially-crafted name. (CVE-2014-3474)
It was found that some email addresses were
Red Hat
openstack-horizon: multiple XSS flaws
vendor_redhat·2014-07-08·CVSS 4.3
CVE-2014-3473 [MEDIUM] CWE-79 openstack-horizon: multiple XSS flaws
openstack-horizon: multiple XSS flaws
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2, when used with Heat, allows remote Orchestration template owners or catalogs to inject arbitrary web script or HTML via a crafted template.
A cross-site scripting (XSS) flaw was found in the way orchestration templates were handled. An owner of such a template could use this flaw to perform XSS attacks against other Horizon users. (CVE-2014-3473)
It was found that network names were not sanitized. A malicious user could use this flaw to perform XSS attacks against other Horizon users by creating a network with a specially-crafted name. (CVE-
Debian
CVE-2014-3474: horizon - Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.in...
vendor_debian·2014·CVSS 3.5
CVE-2014-3474 [LOW] CVE-2014-3474: horizon - Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.in...
Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name.
Scope: local
bookworm: resolved (fixed in 2014.1.1-3)
bullseye: resolved (fixed in 2014.1.1-3)
forky: resolved (fixed in 2014.1.1-3)
sid: resolved (fixed in 2014.1.1-3)
trixie: resolved (fixed in 2014.1.1-3)
GHSA
OpenStack Horizon Cross-site scripting (XSS) vulnerability
ghsa·2022-05-13
CVE-2014-3474 [LOW] CWE-79 OpenStack Horizon Cross-site scripting (XSS) vulnerability
OpenStack Horizon Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in `horizon/static/horizon/js/horizon.instances.js` in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name.
OSV
OpenStack Horizon Cross-site scripting (XSS) vulnerability
osv·2022-05-13
CVE-2014-3474 [LOW] OpenStack Horizon Cross-site scripting (XSS) vulnerability
OpenStack Horizon Cross-site scripting (XSS) vulnerability
Cross-site scripting (XSS) vulnerability in `horizon/static/horizon/js/horizon.instances.js` in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name.
OSV
CVE-2014-3474: Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon
osv·2014-10-31·CVSS 3.5
CVE-2014-3474 [LOW] CVE-2014-3474: Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon
Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name.
OSV
horizon vulnerabilities
osv·2014-08-21·CVSS 4.3
[MEDIUM] horizon vulnerabilities
horizon vulnerabilities
Jason Hullinger discovered that OpenStack Horizon did not properly perform
input sanitization on Heat templates. If a user were tricked into using a
specially crafted Heat template, an attacker could conduct cross-site
scripting attacks. With cross-site scripting vulnerabilities, if a user
were tricked into viewing server output during a crafted server request, a
remote attacker could exploit this to modify the contents, or steal
confidential data, within the same domain. (CVE-2014-3473)
Craig Lorentzen discovered that OpenStack Horizon did not properly perform
input sanitization when creating networks. If a user were tricked into
launching an image using the crafted network name, an attacker could
conduct cross-site scripting attacks. (CVE-2014-3474)
Michael Xin
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 python-django-horizon: openstack-horizon: multiple XSS flaws [epel-6]
bugzilla·2014-07-10·CVSS 4.3
CVE-2014-3473 [MEDIUM] CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 python-django-horizon: openstack-horizon: multiple XSS flaws [epel-6]
CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 python-django-horizon: openstack-horizon: multiple XSS flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 python-django-horizon: openstack-horizon: multiple XSS flaws [fedora-all]
bugzilla·2014-07-10·CVSS 4.3
CVE-2014-3473 [MEDIUM] CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 python-django-horizon: openstack-horizon: multiple XSS flaws [fedora-all]
CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 python-django-horizon: openstack-horizon: multiple XSS flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 CVE-2014-8578 openstack-horizon: multiple XSS flaws
bugzilla·2014-07-03·CVSS 4.3
CVE-2014-3473 [MEDIUM] CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 CVE-2014-8578 openstack-horizon: multiple XSS flaws
CVE-2014-3473 CVE-2014-3474 CVE-2014-3475 CVE-2014-8578 openstack-horizon: multiple XSS flaws
Multiple XSS vulnerabilities were reported in OpenStack Horizon:
Jason Hullinger from Hewlett Packard, Craig Lorentzen from Cisco and Michael Xin from Rackspace reported 3 cross-site scripting (XSS) vulnerabilities in Horizon. A malicious Orchestration template owner or catalog may conduct an XSS attack once a corrupted template is used in the Orchestration/Stack section of Horizon (CVE-2014-3473). A malicious Horizon user may store an XSS attack by creating a network with a corrupted name (CVE-2014-3474). A malicious Horizon administrator may store an XSS attack by creating a user with a corrupted email address (CVE-2014-3475). Once executed in a legitimate context these attacks may result in p
http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlhttp://www.openwall.com/lists/oss-security/2014/07/08/6http://www.securityfocus.com/bid/68460https://bugs.launchpad.net/horizon/+bug/1322197https://review.openstack.org/#/c/105477http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlhttp://www.openwall.com/lists/oss-security/2014/07/08/6http://www.securityfocus.com/bid/68460https://bugs.launchpad.net/horizon/+bug/1322197https://review.openstack.org/#/c/105477
2014-10-31
Published