Bug 1034153 - (CVE-2013-6858) CVE-2013-6858 openstack: horizon multiple XSS vulnerabilities.
CVE-2013-6858 openstack: horizon multiple XSS vulnerabilities.
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
: Security
: CVE-2013-6406 (view as bug list)
Depends On: 1035910 1035911 1035912 1035913 1035914
Blocks: 1034155 1035915
  Show dependency treegraph
Reported: 2013-11-25 05:51 EST by Ratul Gupta
Modified: 2016-04-26 20:53 EDT (History)
17 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2014-04-14 19:09:51 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
cve-2013-6858-master-icehouse.patch (3.42 KB, patch)
2013-12-06 12:38 EST, Kurt Seifried
no flags Details | Diff
cve-2013-6858-stable-havana.patch (3.44 KB, patch)
2013-12-06 12:39 EST, Kurt Seifried
no flags Details | Diff
cve-2013-6858-stable-grizzly.patch (3.35 KB, patch)
2013-12-06 12:40 EST, Kurt Seifried
no flags Details | Diff

  None (edit)
Description Ratul Gupta 2013-11-25 05:51:04 EST
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-6858 to the following vulnerability:

Name: CVE-2013-6858
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6858
Assigned: 20131123
Reference: https://bugs.launchpad.net/horizon/+bug/1247675
Reference: SECUNIA:55770
Reference: http://secunia.com/advisories/55770

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
Comment 1 Matthias Runge 2013-11-25 06:19:34 EST
fix proposed upstream: https://review.openstack.org/#/c/58256/ (it's a backport)
Comment 2 Kurt Seifried 2013-12-03 23:12:11 EST
*** Bug 1035907 has been marked as a duplicate of this bug. ***
Comment 3 Vincent Danen 2013-12-06 11:38:48 EST
Icehouse (development branch) fix:

Havana fix:

Grizzly fix:

Cisco PSIRT reported a vulnerability in the OpenStack Horizon dashboard. By embedding HTML tags in an Instance Name, a tenant may execute a script within an administrator's browser resulting in a cross-site scripting (XSS) attack. Only setups using the Horizon dashboard are affected.
Comment 4 Kurt Seifried 2013-12-06 12:38:53 EST
Created attachment 833693 [details]
Comment 5 Kurt Seifried 2013-12-06 12:39:38 EST
Created attachment 833694 [details]
Comment 6 Kurt Seifried 2013-12-06 12:40:06 EST
Created attachment 833696 [details]
Comment 7 Matthias Runge 2013-12-09 02:43:15 EST
for Icehouse and (esp. Havana), packages are already built and fixes are included for a while right now.

For grizzly, the patch has not been merged upstream yet.
Comment 9 errata-xmlrpc 2014-04-03 16:21:30 EDT
This issue has been addressed in following products:

  OpenStack 3 for RHEL 6

Via RHSA-2014:0365 https://rhn.redhat.com/errata/RHSA-2014-0365.html

Note You need to log in before you can comment on or make changes to this bug.