4.3
CVSSv2

CVE-2013-6858

Published: 23/11/2013 Updated: 09/03/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and previous versions allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack horizon

opensuse opensuse 13.1

canonical ubuntu linux 12.10

canonical ubuntu linux 13.04

canonical ubuntu linux 13.10

Vendor Advisories

Debian Bug report logs - #730752 horizon: CVE-2013-6858: persistent XSS vulnerability Package: horizon; Maintainer for horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Henri Salo <henri@nervfi> Date: Fri, 29 Nov 2013 07:54:02 UTC Severity: important Tags: fixed-upstream, security, upstre ...
Horizon could be made to expose sensitive information over the network ...