CVE-2017-7400
published 2017-04-03CVE-2017-7400: OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation…
PriorityP419medium4.8CVSS 3.0
AVNACLPRHUIRSCCLILAN
EPSS
1.05%
60.7th percentile
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 3:10.0.1-1 (bookworm) | horizon 3:10.0.1-1 (bookworm) |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | >= 0 < 3:10.0.1-1 | 3:10.0.1-1 |
| openstack | horizon | >= 0 < 3:10.0.1-1 | 3:10.0.1-1 |
| openstack | horizon | >= 0 < 3:10.0.1-1 | 3:10.0.1-1 |
| openstack | horizon | >= 0 < 3:10.0.1-1 | 3:10.0.1-1 |
| openstack | horizon | >= 10.0 < 10.0.3 | 10.0.3 |
| openstack | horizon | >= 11.0.0 < 11.0.1 | 11.0.1 |
| openstack | horizon | >= 9.0 < 9.1.2 | 9.1.2 |
CVSS provenance
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv4.8MEDIUM
vendor_debian4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Horizon Cross-site Scripting (XSS)
ghsa·2022-05-14
CVE-2017-7400 [MEDIUM] CWE-79 OpenStack Horizon Cross-site Scripting (XSS)
OpenStack Horizon Cross-site Scripting (XSS)
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
OSV
OpenStack Horizon Cross-site Scripting (XSS)
osv·2022-05-14
CVE-2017-7400 [MEDIUM] OpenStack Horizon Cross-site Scripting (XSS)
OpenStack Horizon Cross-site Scripting (XSS)
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
OSV
CVE-2017-7400: OpenStack Horizon 9
osv·2017-04-03·CVSS 4.8
CVE-2017-7400 [MEDIUM] CVE-2017-7400: OpenStack Horizon 9
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
Red Hat
python-django-horizon: XSS in federation mappings UI
vendor_redhat·2017-03-03·CVSS 4.8
CVE-2017-7400 [MEDIUM] CWE-79 python-django-horizon: XSS in federation mappings UI
python-django-horizon: XSS in federation mappings UI
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
A cross-site scripting flaw was discovered in the OpenStack dashboard (horizon) which allowed remote authenticated administrators to conduct XSS attacks using a crafted federation mapping rule. For this flaw to be exploited, federation mapping must be enabled in the dashboard.
Package: python-django-horizon (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: python-django-horizon (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Package: python-django-horizon (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - N
Debian
CVE-2017-7400: horizon - OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remo...
vendor_debian·2017·CVSS 4.8
CVE-2017-7400 [MEDIUM] CVE-2017-7400: horizon - OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remo...
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
Scope: local
bookworm: resolved (fixed in 3:10.0.1-1)
bullseye: resolved (fixed in 3:10.0.1-1)
forky: resolved (fixed in 3:10.0.1-1)
sid: resolved (fixed in 3:10.0.1-1)
trixie: resolved (fixed in 3:10.0.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7400 python-django-horizon: XSS in federation mappings UI [openstack-rdo]
bugzilla·2017-04-21·CVSS 4.8
CVE-2017-7400 [MEDIUM] CVE-2017-7400 python-django-horizon: XSS in federation mappings UI [openstack-rdo]
CVE-2017-7400 python-django-horizon: XSS in federation mappings UI [openstack-rdo]
This as an RDO Project security tracking bug against python-django-horizon. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2017-7400 python-django-horizon: XSS in federation mappings UI
bugzilla·2017-04-06·CVSS 4.8
CVE-2017-7400 [MEDIUM] CVE-2017-7400 python-django-horizon: XSS in federation mappings UI
CVE-2017-7400 python-django-horizon: XSS in federation mappings UI
OpenStack Horizon allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
Upstream bug:
https://bugs.launchpad.net/horizon/+bug/1667086
Discussion:
Upstream patches:
https://review.openstack.org/442455 (Mitaka)
https://review.openstack.org/442454 (Newton)
https://review.openstack.org/442453 (Ocata)
https://review.openstack.org/442277 (Pike)
---
Created python-django-horizon tracking bugs for this issue:
Affects: openstack-rdo [bug 1444276]
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 10.0 (Newton)
Via RHSA-2017:1598 https://access.redhat.com/errata/RHSA-2017:1598
---
This issue has been addressed in the following products:
http://www.securityfocus.com/bid/97324https://access.redhat.com/errata/RHSA-2017:1598https://access.redhat.com/errata/RHSA-2017:1739https://launchpad.net/bugs/1667086http://www.securityfocus.com/bid/97324https://access.redhat.com/errata/RHSA-2017:1598https://access.redhat.com/errata/RHSA-2017:1739https://launchpad.net/bugs/1667086
2017-04-03
Published