OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/97324 | vdb entry third party advisory |
https://launchpad.net/bugs/1667086 | |
https://access.redhat.com/errata/RHSA-2017:1598 | vendor advisory |
https://access.redhat.com/errata/RHSA-2017:1739 | vendor advisory |