Lucene search

K
redhatRedHatRHSA-2014:0365
HistoryApr 03, 2014 - 12:00 a.m.

(RHSA-2014:0365) Moderate: python-django-horizon security and bug fix update

2014-04-0300:00:00
access.redhat.com
12

0.001 Low

EPSS

Percentile

48.2%

OpenStack Dashboard (horizon) provides administrators and users a graphical
interface to access, provision and automate cloud-based resources.
The dashboard allows cloud administrators to get an overall view of the
size and state of the cloud and it provides end-users a self-service portal
to provision their own resources within the limits set by administrators.

A flaw was found in the way OpenStack Dashboard sanitized the Instance Name
string. By embedding HTML tags in an Instance Name, a remote attacker could
use this flaw to execute a script within a victim’s browser, resulting in a
cross-site scripting (XSS) attack. Note that only setups using OpenStack
Dashboard were affected. (CVE-2013-6858)

The python-django-horizon packages have been upgraded to upstream version
2013.1.5, which provides a number of bug fixes over the previous version.
(BZ#1080584)

All python-django-horizon users are advised to upgrade to these updated
packages, which correct these issues.