First published: Mon Sep 12 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form.
Credit: meissner@suse.de security@opentext.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/manila-ui | <2.5.1 | 2.5.1 |
Red Hat OpenStack for IBM Power | =7.0 | |
Red Hat OpenStack for IBM Power | =8 | |
Red Hat OpenStack for IBM Power | =9 | |
OpenStack Manila | <=2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6519 has a medium severity rating due to the potential for remote authenticated users to exploit the XSS vulnerability.
To fix CVE-2016-6519, you should upgrade the OpenStack Manila UI to version 2.5.1 or later.
CVE-2016-6519 affects OpenStack Manila versions prior to 2.5.1, as well as Red Hat OpenStack versions 7.0, 8, and 9.
CVE-2016-6519 is classified as a Cross-Site Scripting (XSS) vulnerability.
No, CVE-2016-6519 can only be exploited by remote authenticated users.