REDHAT-BUG-1439626: XSS
OpenStack Horizon allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
Upstream bug:
https://bugs.launchpad.net/horizon/+bug/1667086
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1439626?
The severity of REDHAT-BUG-1439626 is considered high due to the potential for XSS attacks by remote authenticated administrators.
How do I fix REDHAT-BUG-1439626?
To fix REDHAT-BUG-1439626, ensure that you update OpenStack Horizon to the latest version where this vulnerability has been addressed.
Who is affected by REDHAT-BUG-1439626?
REDHAT-BUG-1439626 affects any instance of OpenStack Horizon where remote authenticated administrators have access to the federation mapping feature.
What types of attacks can be executed due to REDHAT-BUG-1439626?
Due to REDHAT-BUG-1439626, attackers can execute cross-site scripting (XSS) attacks against the application.
Is there a workaround for REDHAT-BUG-1439626 if I cannot upgrade immediately?
While not ideal, restricting access to the federation mapping feature for remote authenticated administrators can act as a temporary workaround for REDHAT-BUG-1439626.