CVE-2014-3475: XSS
Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-8578.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3475?
CVE-2014-3475 is classified as a medium severity vulnerability due to its potential impact on web application security.
How do I fix CVE-2014-3475?
To fix CVE-2014-3475, update OpenStack Horizon to version 2013.2.4 or later, 2014.1.2 or later, or Juno-2 or later.
What systems are affected by CVE-2014-3475?
CVE-2014-3475 affects OpenStack Horizon versions prior to 2013.2.4 and 2014.1.2, as well as Juno-1.
What type of vulnerability is CVE-2014-3475?
CVE-2014-3475 is a cross-site scripting (XSS) vulnerability that allows remote administrators to inject arbitrary web script or HTML.
Can CVE-2014-3475 impact user data?
Yes, CVE-2014-3475 can potentially impact user data by allowing attackers to execute malicious scripts in the context of the user's browser.