Skip to main content

Vendor/product archive

openstack / horizon CVEs

Beta · best-effort

22 CVEs tagged to openstack / horizon0 Critical, 0 High, 17 Medium, 5 Low, 0 Unrated.

CVE-2022-45582

Published Aug 22, 2023

Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29565

Published Dec 4, 2020

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parame…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5476

Published Dec 30, 2019

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7400

Published Apr 3, 2017

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3988

Published May 19, 2015

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metad…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8578

Published Oct 31, 2014

Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote adminis…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3475

Published Oct 31, 2014

Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3474

Published Oct 31, 2014

Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 bef…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3473

Published Oct 31, 2014

Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3594

Published Aug 22, 2014

Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows r…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4471

Published May 14, 2014

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remot…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0157

Published Apr 15, 2014

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3542

Published Sep 5, 2012

OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a reque…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3540

Published Sep 5, 2012

Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbitrary web sites and conduct phi…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2144

Published Jun 5, 2012

Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2094

Published Jun 5, 2012

Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-22 of 22 CVEsPage 1 of 1