User: Password:
Subscribe / Log in / New account

horizon: information disclosure

Package(s):horizon CVE #(s):CVE-2013-6858
Created:December 20, 2013 Updated:April 4, 2014

From the Ubuntu advisory:

Chris Chapman discovered cross-site scripting (XSS) vulnerabilities in Horizon via the Volumes and Network Topology pages. An authenticated attacker could exploit these to conduct stored cross-site scripting (XSS) attacks against users viewing these pages in order to modify the contents or steal confidential data within the same domain.

openSUSE openSUSE-SU-2015:0078-1 openstack-dashboard 2015-01-19
Red Hat RHSA-2014:0365-01 python-django-horizon 2014-04-03
Ubuntu USN-2062-1 horizon 2013-12-19

(Log in to post comments)

Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds