CVE-2016-4428
python-django-horizon: XSS in client side template
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
Vulnerabilidad de XSS en OpenStack Dashboard (Horizon) 8.0.1 y versiones anteriores y 9.0.0 hasta la versiĆ³n 9.0.1 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrario inyectando una plantilla AngularJS en un formulario del cuadro de mandos.
A DOM-based, cross-site scripting vulnerability was found in the OpenStack dashboard, where user input was not filtered correctly. An authenticated dashboard user could exploit the flaw by injecting an AngularJS template into a dashboard form (for example, using an image's description), triggering the vulnerability when another user browsed the affected page. As a result, this flaw could result in user accounts being compromised (for example, user-access credentials being stolen).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-05-02 CVE Reserved
- 2016-06-22 CVE Published
- 2023-09-04 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
https://bugs.launchpad.net/horizon/+bug/1567673 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2016/06/17/4 | 2023-02-12 | |
https://review.openstack.org/329996 | 2023-02-12 | |
https://review.openstack.org/329997 | 2023-02-12 | |
https://review.openstack.org/329998 | 2023-02-12 | |
https://security.openstack.org/ossa/OSSA-2016-010.html | 2023-02-12 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2016/dsa-3617 | 2023-02-12 | |
https://access.redhat.com/errata/RHSA-2016:1268 | 2023-02-12 | |
https://access.redhat.com/errata/RHSA-2016:1269 | 2023-02-12 | |
https://access.redhat.com/errata/RHSA-2016:1270 | 2023-02-12 | |
https://access.redhat.com/errata/RHSA-2016:1271 | 2023-02-12 | |
https://access.redhat.com/errata/RHSA-2016:1272 | 2023-02-12 | |
https://access.redhat.com/security/cve/CVE-2016-4428 | 2016-06-21 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1343982 | 2016-06-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 5.0 Search vendor "Redhat" for product "Openstack" and version "5.0" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 6.0 Search vendor "Redhat" for product "Enterprise Linux" and version "6.0" | - |
Safe
|
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 5.0 Search vendor "Redhat" for product "Openstack" and version "5.0" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 7.0 Search vendor "Redhat" for product "Enterprise Linux" and version "7.0" | - |
Safe
|
Openstack Search vendor "Openstack" | Horizon Search vendor "Openstack" for product "Horizon" | >= 8.0.0 <= 8.0.1 Search vendor "Openstack" for product "Horizon" and version " >= 8.0.0 <= 8.0.1" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Horizon Search vendor "Openstack" for product "Horizon" | 9.0.0 Search vendor "Openstack" for product "Horizon" and version "9.0.0" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Horizon Search vendor "Openstack" for product "Horizon" | 9.0.1 Search vendor "Openstack" for product "Horizon" and version "9.0.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 6.0 Search vendor "Redhat" for product "Openstack" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 7.0 Search vendor "Redhat" for product "Openstack" and version "7.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 8 Search vendor "Redhat" for product "Openstack" and version "8" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|