OSSA-2017-003: XSS in Horizon federation mappings UI

Date:

April 04, 2017

CVE:

CVE-2017-7400

Affects

  • Horizon: >=9.0.0 <=9.1.1, >=10.0.0 <=10.0.2, ==11.0.0

Description

Eric Brown from VMware reported a vulnerability in Horizon. By creating a malicious federation mapping, an administrator may conduct a persistent XSS attack. All Horizon setups are affected.

Patches

Credits

  • Eric Brown from VMware (CVE-2017-7400)

References