date: 2013-12-11 id: OSSA-2013-036 title: 'Insufficient sanitization of Instance Name in Horizon' description: 'Cisco PSIRT reported a vulnerability in the OpenStack Horizon dashboard. By embedding HTML tags in an Instance Name, a tenant may execute a script within an administrator''s browser resulting in a cross-site scripting (XSS) attack. Only setups using the Horizon dashboard are affected.' reference: http://lists.openstack.org/pipermail/openstack-announce/2013-December/000173.html affected-products: - product: horizon version: All supported releases vulnerabilities: - cve-id: CVE-2013-6858 impact-assessment: source: 'Red Hat Product Security' rating: moderate assessment: type: CVSS2 score: 4.3 detail: AV:N/AC:M/Au:N/C:N/I:P/A:N classification: source: 'Red Hat Product Security' type: CWE detail: TODO reporters: - name: 'Cisco PSIRT' affiliation: Cisco reported: - CVE-2013-6858 issues: links: - https://launchpad.net/bugs/1247675 type: launchpad reviews: icehouse: - https://review.openstack.org/#/c/55175 havana: - https://review.openstack.org/#/c/58465 grizzly: - https://review.openstack.org/#/c/58820 type: gerrit