VDB
Sign up
—

PYSEC-2026-822

OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting

Quick fix

PYSEC-2026-822 — horizon: upgrade to the fixed version with the command below.

pip install --upgrade 'horizon>=2013.2.4'

Details

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/horizon
Introduced in: 2013.2Fixed in: 2013.2.4
Fixpip install --upgrade 'horizon>=2013.2.4'

References