4.3
CVSSv2

CVE-2015-3219

Published: 20/08/2015 Updated: 24/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 prior to 2014.2.4 and 2015.1.x prior to 2015.1.1 allows remote malicious users to inject arbitrary web script or HTML via the description parameter in a heat template, which is not properly handled in the help_text attribute in the Field class.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

openstack horizon 2014.2.0

openstack horizon 2014.2.1

openstack horizon 2015.1.0

openstack horizon 2014.2.2

openstack horizon 2014.2.3

oracle solaris 11.2

Vendor Advisories

Debian Bug report logs - #828967 CVE-2016-4428: Possible client side template injection in horizon Package: src:horizon; Maintainer for src:horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Wed, 29 Jun 2016 12:57:02 UTC Severity: important Tags: secur ...
Debian Bug report logs - #788306 horizon: CVE-2015-3219: XSS in Horizon Heat stack creation Package: src:horizon; Maintainer for src:horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 10 Jun 2015 05:39:02 UTC Severity: important Tags: fixe ...