VulnerabilityModified
CVE-2013-6858
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
MEDIUM 4.3EPSS 1.73%
Does this matter?
Lower severity and a low EPSS score (1.73%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.73% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- openstack/horizon · opensuse/opensuse · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/55770Third Party Advisory
- http://secunia.com/advisories/56117Third Party Advisory
- http://www.securityfocus.com/bid/63787Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2062-1Third Party Advisory
- https://bugs.launchpad.net/horizon/+bug/1247675Issue Tracking, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/55770Third Party Advisory
- http://secunia.com/advisories/56117Third Party Advisory
- http://www.securityfocus.com/bid/63787Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2062-1Third Party Advisory
- https://bugs.launchpad.net/horizon/+bug/1247675Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.