OSSA-2017-003: XSS in Horizon federation mappings UI¶
- Date:
April 04, 2017
- CVE:
CVE-2017-7400
Affects¶
Horizon: >=9.0.0 <=9.1.1, >=10.0.0 <=10.0.2, ==11.0.0
Description¶
Eric Brown from VMware reported a vulnerability in Horizon. By creating a malicious federation mapping, an administrator may conduct a persistent XSS attack. All Horizon setups are affected.
Patches¶
https://review.openstack.org/442455 (Mitaka)
https://review.openstack.org/442454 (Newton)
Credits¶
Eric Brown from VMware (CVE-2017-7400)