CVE-2015-3988Cross-site Scripting in Horizon

Severity
3.5LOWNVD
EPSS
0.4%
top 42.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 19
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages2 packages

NVDopenstack/horizon2015.1.0
NVDoracle/solaris11.2

🔴Vulnerability Details

3
GHSA
GHSA-chfp-7692-g532: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 20152022-05-17
OSV
CVE-2015-3988: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 20152015-05-19
CVEList
CVE-2015-3988: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 20152015-05-19

📋Vendor Advisories

2
Red Hat
python-django-horizon: persistent XSS in Horizon metadata dashboard2015-05-01
Debian
CVE-2015-3988: horizon - Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Hori...2015

💬Community

2
Bugzilla
CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard2015-05-19
Bugzilla
CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard [fedora-all]2015-05-19
CVE-2015-3988 — Cross-site Scripting in Horizon | cvebase