Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1222871 - (CVE-2015-3988) CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard
CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashb...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20150501,repor...
: Security
Depends On: 1222873 1222874 1223350 1223351
Blocks: 1222872
  Show dependency treegraph
 
Reported: 2015-05-19 06:41 EDT by Vasyl Kaigorodov
Modified: 2016-04-26 13:45 EDT (History)
22 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A flaw was discovered in the OpenStack dashboard (horizon) handling of metadata. Potentially untrusted data was displayed from OpenStack Image service (glance) images, OpenStack Compute (nova) flavors, or host aggregates without correct sanitization. The flaw could be used by an authenticated user to conduct an XSS attack.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-08-25 22:45:15 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:1679 normal SHIPPED_LIVE Moderate: python-django-horizon security and bug fix update 2015-08-24 20:15:52 EDT

  None (edit)
Description Vasyl Kaigorodov 2015-05-19 06:41:21 EDT
Title: Persistent XSS in Horizon metadata dashboard
Reporter: Sunil Yadav (IBM)
Products: Horizon
Affects: version 2015.1.0

Description:
Sunil Yadav from IBM Security Services reported a persistent XSS in
Horizon. An authenticated user may conduct a persistent XSS attack by
setting a malicious metadata to a Glance image, a Nova flavor or a Host
Aggregate and tricking an administrator to load the update metadata
page. Once executed in a legitimate context this attack may result in a
privilege escalation. All Horizon setups are affected.

Upstream bug:
https://launchpad.net/bugs/1449260

Upstream commit:
https://git.openstack.org/cgit/openstack/horizon/commit/?id=e7f3e0880f4e311c768c413e43317674cb234515
Comment 1 Vasyl Kaigorodov 2015-05-19 06:42:40 EDT
Created python-django-horizon tracking bugs for this issue:

Affects: fedora-all [bug 1222873]
Affects: openstack-rdo [bug 1222874]
Comment 4 errata-xmlrpc 2015-08-24 16:16:05 EDT
This issue has been addressed in the following products:

  OpenStack 6 for RHEL 7

Via RHSA-2015:1679 https://rhn.redhat.com/errata/RHSA-2015-1679.html

Note You need to log in before you can comment on or make changes to this bug.