CVE-2015-3988
published 2015-05-19CVE-2015-3988: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script…
PriorityP414low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.80%
76.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 2015.1.0-2 (bookworm) | horizon 2015.1.0-2 (bookworm) |
| openstack | horizon | — | — |
| openstack | horizon | >= 0 < 2015.1.0-2 | 2015.1.0-2 |
| openstack | horizon | >= 0 < 2015.1.0-2 | 2015.1.0-2 |
| openstack | horizon | >= 0 < 2015.1.0-2 | 2015.1.0-2 |
| openstack | horizon | >= 0 < 2015.1.0-2 | 2015.1.0-2 |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chfp-7692-g532: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015
ghsa_unreviewed·2022-05-17
CVE-2015-3988 [LOW] CWE-79 GHSA-chfp-7692-g532: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
OSV
CVE-2015-3988: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015
osv·2015-05-19·CVSS 3.5
CVE-2015-3988 [LOW] CVE-2015-3988: Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
Red Hat
python-django-horizon: persistent XSS in Horizon metadata dashboard
vendor_redhat·2015-05-01·CVSS 3.5
CVE-2015-3988 [LOW] CWE-79 python-django-horizon: persistent XSS in Horizon metadata dashboard
python-django-horizon: persistent XSS in Horizon metadata dashboard
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
A flaw was discovered in the OpenStack dashboard (horizon) handling of metadata. Potentially untrusted data was displayed from OpenStack Image service (glance) images, OpenStack Compute (nova) flavors, or host aggregates without correct sanitization. The flaw could be used by an authenticated user to conduct an XSS attack.
Package: python-django-horizon (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: python-django-horizon (Red Hat Enterprise Li
Debian
CVE-2015-3988: horizon - Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Hori...
vendor_debian·2015·CVSS 3.5
CVE-2015-3988 [LOW] CVE-2015-3988: horizon - Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Hori...
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate.
Scope: local
bookworm: resolved (fixed in 2015.1.0-2)
bullseye: resolved (fixed in 2015.1.0-2)
forky: resolved (fixed in 2015.1.0-2)
sid: resolved (fixed in 2015.1.0-2)
trixie: resolved (fixed in 2015.1.0-2)
No detection rules found.
No public exploits indexed.
arXiv
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 with New Scoring and Data Sources
arxiv_fulltext·2025-08-18
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 with New Scoring and Data Sources
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 with New Scoring and Data Sources
[1,2]Tadeu Freitas
[1]Carlos Novo
[1]Inês Dutra
[1]João Soares
[1,2]Manuel E. Correia
[3]Benham Shariati
[4]Rolando Martins
FREITAS et al.
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 with New Scoring and Data Sources
[1]Department of Computer Science, Faculty of Sciences of University of Porto, Porto, Portugal
[2]Centre Advanced Computing Systems, Institute for Systems and Computer Engineering, Technology and Science, Porto, Portugal
[3]UMBC, University of Maryland, Baltimore County,Baltimore, USA
[4]SafeHelm, lda, Porto, Portugal
Corresponding author Tadeu Freitas. [email protected]
[Abstract]Intrusion Tolerant Systems (ITSs) have become increasingly
arXiv
HAL 9000: a Risk Manager for ITSs
arxiv_fulltext·2025-03-21
HAL 9000: a Risk Manager for ITSs
HAL 9000: a Risk Manager for ITSs
This work is financed by National Funds through the Portuguese funding agency, FCT - Fundação para a Ciência e a Tecnologia, within project UIDB/50014/2020.
DOI 10.54499/UIDB/50014/2020 https://doi.org/10.54499/uidb/50014/2020
This work was funded by 2021.08532.BD (FCT), and by 2021.04529.BD (FCT).
Tadeu Freitas12, Carlos Novo1, João Soares12, Inês Dutra13,
Manuel E. Correia12, Behnam Shariati4, Rolando Martins15
1Faculty of Sciences, University of Porto, Portugal
2CRACS/INESC-TEC, Portugal
3CINTESIS@RISE, Portugal
4University of Maryland, Baltimore County, USA
5SafeHelm, lda, Porto, Portugal
\tadeufreitas, joao.soares, mdcorrei, carlosnovo, ines\@fc.up.pt,
[email protected], [email protected]
## Abstract
HAL 9000 is an Intrusion Tolerant Systems
Bugzilla
CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard
bugzilla·2015-05-19·CVSS 3.5
CVE-2015-3988 [LOW] CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard
CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard
Title: Persistent XSS in Horizon metadata dashboard
Reporter: Sunil Yadav (IBM)
Products: Horizon
Affects: version 2015.1.0
Description:
Sunil Yadav from IBM Security Services reported a persistent XSS in
Horizon. An authenticated user may conduct a persistent XSS attack by
setting a malicious metadata to a Glance image, a Nova flavor or a Host
Aggregate and tricking an administrator to load the update metadata
page. Once executed in a legitimate context this attack may result in a
privilege escalation. All Horizon setups are affected.
Upstream bug:
https://launchpad.net/bugs/1449260
Upstream commit:
https://git.openstack.org/cgit/openstack/horizon/commit/?id=e7f3e0880f4e311c768c413e43317674cb234515
Dis
Bugzilla
CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard [fedora-all]
bugzilla·2015-05-19·CVSS 3.5
CVE-2015-3988 [LOW] CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard [fedora-all]
CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
http://rhn.redhat.com/errata/RHSA-2015-1679.htmlhttp://www.openwall.com/lists/oss-security/2015/05/12/9http://www.openwall.com/lists/oss-security/2015/05/14/14http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/74666https://security.openstack.org/ossa/OSSA-2015-009.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1679.htmlhttp://www.openwall.com/lists/oss-security/2015/05/12/9http://www.openwall.com/lists/oss-security/2015/05/14/14http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/74666https://security.openstack.org/ossa/OSSA-2015-009.html
2015-05-19
Published