CVE-2016-4428: XSS
Beth Lancaster and Brandon Sawyers from Virginia Tech reported a vulnerability in Horizon. By injecting Angularjs template in dashboard forms, such as image's description, an authenticated user may trigger a cross-site-scripting vulnerability when another user browses the affected pages. It may result in potential assets theft like user access credentials. All Horizon setups are affected.
Other sources
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
— GitHub
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4428?
CVE-2016-4428 has a medium severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2016-4428?
To fix CVE-2016-4428, upgrade Horizon to at least version 9.1.0 or 8.0.2 depending on your current version.
What software is affected by CVE-2016-4428?
CVE-2016-4428 affects multiple versions of OpenStack Horizon and Red Hat OpenStack.
Who reported CVE-2016-4428?
CVE-2016-4428 was reported by Beth Lancaster and Brandon Sawyers from Virginia Tech.
Can CVE-2016-4428 be exploited by unauthenticated users?
No, CVE-2016-4428 requires an authenticated user to exploit the cross-site scripting vulnerability.