CVE-2014-3474
openstack-horizon: multiple XSS flaws
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name.
Vulnerabilidad de XSS en horizon/static/horizon/js/horizon.instances.js en el menú Launch Instance en OpenStack Dashboard (Horizon) anterior a 2013.2.4, 2014.1 anterior a 2014.1.2, y Juno anterior a Juno-2 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de un nombre de red.
Jason Hullinger discovered that OpenStack Horizon did not properly perform input sanitization on Heat templates. If a user were tricked into using a specially crafted Heat template, an attacker could conduct cross-site scripting attacks. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. Craig Lorentzen discovered that OpenStack Horizon did not properly perform input sanitization when creating networks. If a user were tricked into launching an image using the crafted network name, an attacker could conduct cross-site scripting attacks. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-05-14 CVE Reserved
- 2014-07-24 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-04-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/68460 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://bugs.launchpad.net/horizon/+bug/1322197 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2014/07/08/6 | 2023-02-13 | |
https://review.openstack.org/#/c/105477 | 2023-02-13 |
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.html | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2014-3474 | 2014-09-15 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1116090 | 2014-09-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Horizon Search vendor "Openstack" for product "Horizon" | >= 2013.2 < 2013.2.4 Search vendor "Openstack" for product "Horizon" and version " >= 2013.2 < 2013.2.4" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Horizon Search vendor "Openstack" for product "Horizon" | >= 2014.1 < 2014.1.2 Search vendor "Openstack" for product "Horizon" and version " >= 2014.1 < 2014.1.2" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Horizon Search vendor "Openstack" for product "Horizon" | juno-1 Search vendor "Openstack" for product "Horizon" and version "juno-1" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 13.1 Search vendor "Opensuse" for product "Opensuse" and version "13.1" | - |
Affected
|