Vulnerabilities
Vulnerable Software
Openstack:  >> Horizon  >> 2013.1.1  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475.
CVSS Score
3.5
EPSS Score
0.003
Published
2014-10-31
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.
CVSS Score
5.5
EPSS Score
0.002
Published
2014-05-14
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
CVSS Score
4.3
EPSS Score
0.008
Published
2013-11-23


Contact Us

Shodan ® - All rights reserved