VDB
KO
MEDIUM 4.8

GHSA-47vp-44v9-rhgq

OpenStack Horizon Cross-site Scripting (XSS)

Details

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / horizon
Introduced in: 9.0 Fixed in: 9.1.2
Fix pip install --upgrade 'horizon>=9.1.2'
PyPI / horizon
Introduced in: 10.0 Fixed in: 10.0.3
Fix pip install --upgrade 'horizon>=10.0.3'
PyPI / horizon
Introduced in: 11.0.0 Fixed in: 11.0.1
Fix pip install --upgrade 'horizon>=11.0.1'

References