CVE-2015-3219: XSS
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parameter in a heat template, which is not properly handled in the helptext attribute in the Field class.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3219?
CVE-2015-3219 has a medium severity rating due to the potential for cross-site scripting attacks.
How do I fix CVE-2015-3219?
To fix CVE-2015-3219, upgrade the OpenStack Dashboard (Horizon) to version 2014.2.4 or later, or 2015.1.1 or later.
What are the affected versions for CVE-2015-3219?
CVE-2015-3219 affects OpenStack Horizon versions 2014.2.0 through 2014.2.3 and 2015.1.0.
Can CVE-2015-3219 be exploited remotely?
Yes, CVE-2015-3219 can be exploited by remote attackers through the description parameter in heat templates.
Is there a specific software or package that needs upgrading for CVE-2015-3219?
Yes, the package requiring an upgrade is 'horizon' to version 8.0.0a0 or higher for mitigation of CVE-2015-3219.