Comment 18 for bug 1247675

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: Persistent XSS in OpenStack Web UI for Instances (CVE-2013-6858)

Proposed impact description...
-----

Title: Insufficient sanitization of Instance Name in Horizon
Reporter: Cisco PSIRT
Products: Horizon
Affects: All supported releases

Description:
Cisco PSIRT reported a vulnerability in the OpenStack Horizon dashboard. By embedding HTML tags in an Instance Name, a tenant may execute a script within an administrator's browser resulting in a cross-site scripting (XSS) attack. Only setups using the Horizon dashboard are affected.