OpenStack Horizon allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping. Upstream bug: https://bugs.launchpad.net/horizon/+bug/1667086
Upstream patches: https://review.openstack.org/442455 (Mitaka) https://review.openstack.org/442454 (Newton) https://review.openstack.org/442453 (Ocata) https://review.openstack.org/442277 (Pike)
Created python-django-horizon tracking bugs for this issue: Affects: openstack-rdo [bug 1444276]
This issue has been addressed in the following products: Red Hat OpenStack Platform 10.0 (Newton) Via RHSA-2017:1598 https://access.redhat.com/errata/RHSA-2017:1598
This issue has been addressed in the following products: Red Hat OpenStack Platform 9.0 (Mitaka) Via RHSA-2017:1739 https://access.redhat.com/errata/RHSA-2017:1739