CVE-2017-7400: XSS
OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
Other sources
OpenStack Horizon allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
Upstream bug:
https://bugs.launchpad.net/horizon/+bug/1667086
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/horizonto a version that resolves this vulnerability.Fixed in 11.0.1 - Upgrade
Upgrade
pip/horizonto a version that resolves this vulnerability.Fixed in 10.0.3 - Upgrade
Upgrade
pip/horizonto a version that resolves this vulnerability.Fixed in 9.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7400?
CVE-2017-7400 has a medium severity rating due to its potential for XSS attacks.
How do I fix CVE-2017-7400?
To fix CVE-2017-7400, update OpenStack Horizon to version 9.1.2, 10.0.3, or 11.0.1.
What versions of OpenStack Horizon are affected by CVE-2017-7400?
CVE-2017-7400 affects OpenStack Horizon versions 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0.
What type of attack is related to CVE-2017-7400?
CVE-2017-7400 is related to Cross-Site Scripting (XSS) attacks that can be performed by remote authenticated administrators.
Can CVE-2017-7400 be exploited remotely?
Yes, CVE-2017-7400 can be exploited remotely by authenticated administrators through crafted federation mappings.