Vulnerability CVE-2014-3594


Published: 2014-08-22

Description:
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

Vendor: Openstack
Product: Horizon 
Version:
juno-2
juno-1
2014.1.1
2014.1
2013.2.3
2013.2.2
2013.2.1
2013.2
2013.1
Vendor: Novell
Product: Opensuse 
Version: 13.1;
Vendor: Opensuse
Product: Opensuse 
Version: 13.1;

CVSS2 => (AV:N/AC:M/Au:S/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.html
http://rhn.redhat.com/errata/RHSA-2014-1335.html
http://rhn.redhat.com/errata/RHSA-2014-1336.html
http://seclists.org/oss-sec/2014/q3/413
http://www.securityfocus.com/bid/69291
https://bugs.launchpad.net/horizon/+bug/1349491
https://exchange.xforce.ibmcloud.com/vulnerabilities/95378
https://review.openstack.org/#/c/115310
https://review.openstack.org/#/c/115311
https://review.openstack.org/#/c/115313/

Related CVE
CVE-2015-7542
An issue exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.
CVE-2019-18622
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
CVE-2019-14869
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating ...
CVE-2019-11139
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
CVE-2019-11135
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
CVE-2011-1588
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
CVE-2011-1490
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of...
CVE-2011-1489
A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial o...

Copyright 2019, cxsecurity.com

 

Back to Top