Bug 1222871 (CVE-2015-3988) - CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashboard
Summary: CVE-2015-3988 python-django-horizon: persistent XSS in Horizon metadata dashb...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2015-3988
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1222873 1222874 1223350 1223351
Blocks: 1222872
TreeView+ depends on / blocked
 
Reported: 2015-05-19 10:41 UTC by Vasyl Kaigorodov
Modified: 2021-02-17 05:17 UTC (History)
22 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A flaw was discovered in the OpenStack dashboard (horizon) handling of metadata. Potentially untrusted data was displayed from OpenStack Image service (glance) images, OpenStack Compute (nova) flavors, or host aggregates without correct sanitization. The flaw could be used by an authenticated user to conduct an XSS attack.
Clone Of:
Environment:
Last Closed: 2015-08-26 02:45:15 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:1679 0 normal SHIPPED_LIVE Moderate: python-django-horizon security and bug fix update 2015-08-25 00:15:52 UTC

Description Vasyl Kaigorodov 2015-05-19 10:41:21 UTC
Title: Persistent XSS in Horizon metadata dashboard
Reporter: Sunil Yadav (IBM)
Products: Horizon
Affects: version 2015.1.0

Description:
Sunil Yadav from IBM Security Services reported a persistent XSS in
Horizon. An authenticated user may conduct a persistent XSS attack by
setting a malicious metadata to a Glance image, a Nova flavor or a Host
Aggregate and tricking an administrator to load the update metadata
page. Once executed in a legitimate context this attack may result in a
privilege escalation. All Horizon setups are affected.

Upstream bug:
https://launchpad.net/bugs/1449260

Upstream commit:
https://git.openstack.org/cgit/openstack/horizon/commit/?id=e7f3e0880f4e311c768c413e43317674cb234515

Comment 1 Vasyl Kaigorodov 2015-05-19 10:42:40 UTC
Created python-django-horizon tracking bugs for this issue:

Affects: fedora-all [bug 1222873]
Affects: openstack-rdo [bug 1222874]

Comment 4 errata-xmlrpc 2015-08-24 20:16:05 UTC
This issue has been addressed in the following products:

  OpenStack 6 for RHEL 7

Via RHSA-2015:1679 https://rhn.redhat.com/errata/RHSA-2015-1679.html


Note You need to log in before you can comment on or make changes to this bug.