CVE-2014-3594Cross-site Scripting in Horizon

CWE-79Cross-site Scripting11 documents8 sources
Severity
3.5LOWNVD
EPSS
0.6%
top 30.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22
Latest updateMay 13

Description

Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages2 packages

NVDopenstack/horizon2013.22013.2.4+3

Patches

🔴Vulnerability Details

4
OSV
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface2022-05-13
GHSA
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface2022-05-13
OSV
CVE-2014-3594: Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 20132014-08-22
CVEList
CVE-2014-3594: Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 20132014-08-22

📋Vendor Advisories

3
Ubuntu
OpenStack Horizon vulnerabilities2014-08-21
Red Hat
openstack-horizon: persistent XSS in Horizon Host Aggregates interface2014-08-19
Debian
CVE-2014-3594: horizon - Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in Ope...2014

💬Community

3
Bugzilla
CVE-2014-3594 python-django-horizon: openstack-horizon: persistent XSS in Horizon Host Aggregates interface [epel-6]2014-08-20
Bugzilla
CVE-2014-3594 python-django-horizon: openstack-horizon: persistent XSS in Horizon Host Aggregates interface [fedora-all]2014-08-20
Bugzilla
CVE-2014-3594 openstack-horizon: persistent XSS in Horizon Host Aggregates interface2014-08-13
CVE-2014-3594 — Cross-site Scripting in Horizon | cvebase