OSSA-2017-003: XSS in Horizon federation mappings UI

Date:April 04, 2017
CVE:CVE-2017-7400

Affects

  • Horizon: >=9.0.0 <=9.1.1, >=10.0.0 <=10.0.2, ==11.0.0

Description

Eric Brown from VMware reported a vulnerability in Horizon. By creating a malicious federation mapping, an adminstrator may conduct a persistent XSS attack. All Horizon setups are affected.

Credits

  • Eric Brown from VMware (CVE-2017-7400)