First published: Mon Apr 03 2017(Updated: )
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Horizon | =9.0.0 | |
OpenStack Horizon | =9.0.0-b1 | |
OpenStack Horizon | =9.0.0-b2 | |
OpenStack Horizon | =9.0.0-b3 | |
OpenStack Horizon | =9.0.0-rc1 | |
OpenStack Horizon | =9.0.0-rc2 | |
OpenStack Horizon | =9.0.1 | |
OpenStack Horizon | =9.1.0 | |
OpenStack Horizon | =9.1.1 | |
OpenStack Horizon | =10.0.0 | |
OpenStack Horizon | =10.0.0-b1 | |
OpenStack Horizon | =10.0.0-b2 | |
OpenStack Horizon | =10.0.0-b3 | |
OpenStack Horizon | =10.0.0-rc1 | |
OpenStack Horizon | =10.0.0-rc2 | |
OpenStack Horizon | =10.0.0-rc3 | |
OpenStack Horizon | =10.0.1 | |
OpenStack Horizon | =10.0.2 | |
OpenStack Horizon | =11.0.0 | |
pip/horizon | >=11.0.0<11.0.1 | 11.0.1 |
pip/horizon | >=10.0<10.0.3 | 10.0.3 |
pip/horizon | >=9.0<9.1.2 | 9.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7400 has a medium severity rating due to its potential for XSS attacks.
To fix CVE-2017-7400, update OpenStack Horizon to version 9.1.2, 10.0.3, or 11.0.1.
CVE-2017-7400 affects OpenStack Horizon versions 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0.
CVE-2017-7400 is related to Cross-Site Scripting (XSS) attacks that can be performed by remote authenticated administrators.
Yes, CVE-2017-7400 can be exploited remotely by authenticated administrators through crafted federation mappings.