Bug#786741: [PKG-Openstack-devel] Bug#786741: Bug#786741: horizon: CVE-2015-3988: Persistent XSS in Horizon metadata dashboard

2015-05-25 Thread Martin Zobel-Helas
Hi, On Mon May 25, 2015 at 11:47:17 +0200, Martin Zobel-Helas wrote: > Hi, > > On Mon May 25, 2015 at 07:36:15 +0200, Salvatore Bonaccorso wrote: > > Source: horizon > > Version: 2015.1.0-1 > > Severity: important > > Tags: security upstream > > > > Hi, > > > > the following vulnerability was

Bug#786741: [PKG-Openstack-devel] Bug#786741: horizon: CVE-2015-3988: Persistent XSS in Horizon metadata dashboard

2015-05-25 Thread Martin Zobel-Helas
Hi, On Mon May 25, 2015 at 07:36:15 +0200, Salvatore Bonaccorso wrote: > Source: horizon > Version: 2015.1.0-1 > Severity: important > Tags: security upstream > > Hi, > > the following vulnerability was published for horizon. > > CVE-2015-3988[0]: > | Multiple cross-site scripting (XSS) vulner

Bug#786741: horizon: CVE-2015-3988: Persistent XSS in Horizon metadata dashboard

2015-05-25 Thread Salvatore Bonaccorso
Hi I have updated the severity to it due to "An authenticated user may conduct a persistent XSS attack by setting a malicious metadata to a Glance image, a Nova flavor or a Host Aggregate and tricking an administrator to load the update metadata page. Once executed in a legitimate context this att

Bug#786741: horizon: CVE-2015-3988: Persistent XSS in Horizon metadata dashboard

2015-05-24 Thread Salvatore Bonaccorso
Source: horizon Version: 2015.1.0-1 Severity: important Tags: security upstream Hi, the following vulnerability was published for horizon. CVE-2015-3988[0]: | Multiple cross-site scripting (XSS) vulnerabilities in OpenStack | Dashboard (Horizon) 2015.1.0 allow remote authenticated users to | inj