ossa/ossa/OSSA-2012-004.yaml

57 lines
1.2 KiB
YAML

date: 2012-04-17
id: OSSA-2012-004
title: 'XSS vulnerability in Horizon log viewer'
description: 'Matthias Weckbecker reported a vulnerability in Horizon. He noted that
the log viewer refreshing mechanism does not escape the data fetched from guest
consoles. This means that HTML with Javascript code gets interpreted as such, resulting
in the ability to inject code into a dashboard session. '
reference: https://lists.launchpad.net/openstack/msg10211.html
affected-products:
- product: horizon
version: All versions
vulnerabilities:
- cve-id: CVE-2012-2094
impact-assessment:
source: 'Red Hat Product Security'
rating: low
assessment:
type: CVSS2
score: 2.9
detail: AV:N/AC:L/Au:N/C:P/I:N/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Matthias Weckbecker'
affiliation: UNKNOWN
reported:
- CVE-2012-2094
issues:
links:
- https://launchpad.net/bugs/977944
type: launchpad
reviews:
folsom:
- https://review.openstack.org/#/c/6618
essex:
- https://review.openstack.org/#/c/6621
type: gerrit