Bug 852175 (CVE-2013-6858) - VUL-0: CVE-2013-6858: openstack-dashboard: Multiple cross-site scripting (XSS) vulnerabilities
Summary: VUL-0: CVE-2013-6858: openstack-dashboard: Multiple cross-site scripting (XS...
Status: RESOLVED FIXED
: CVE-2013-6406 (view as bug list)
Alias: CVE-2013-6858
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-04-17
Assignee: Bernhard Wiedemann
QA Contact: Security Team bot
URL:
Whiteboard: maint:running:56890:moderate CVSSv2:R...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-25 15:00 UTC by Victor Pereira
Modified: 2016-10-20 10:22 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2013-11-25 15:00:44 UTC
CVE-2013-6858


Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to "Volumes" or "Network Topology" page.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1034153
http://secunia.com/advisories/55770
https://bugs.launchpad.net/horizon/+bug/1247675
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6858
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6858
Comment 1 Swamp Workflow Management 2013-11-25 23:00:29 UTC
bugbot adjusting priority
Comment 2 Sascha Peilicke 2013-11-27 17:28:43 UTC
Fix backported to Grizzly, currently in Cloud:OpenStack:Grizzly:Staging
Comment 3 Alexander Bergmann 2013-12-04 14:06:30 UTC
*** Bug 853043 has been marked as a duplicate of this bug. ***
Comment 4 Sascha Peilicke 2013-12-06 13:48:37 UTC
Meanwhile in Devel:Cloud:2.0:Staging, will submit to SP3:Update after mkcloud passed.
Comment 5 Marcus Meissner 2014-03-28 08:27:51 UTC
was this ever submitted sascha?
Comment 7 Swamp Workflow Management 2014-04-03 15:33:37 UTC
The SWAMPID for this issue is 56890.
This issue was rated as moderate.
Please submit fixed packages until 2014-04-17.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 9 Bernhard Wiedemann 2014-04-09 12:36:04 UTC
openstack-dashboard-branding-SLE needs to be mentioned in the patchinfo
because we have new requires on a new provides in it
Comment 11 Bernhard Wiedemann 2014-11-17 14:28:31 UTC
I think, this one can be closed, since SUSE Cloud 2.0 is EOL
Comment 12 Bernhard Wiedemann 2014-12-12 14:00:27 UTC
This is an autogenerated message for OBS integration:
This bug (852175) was mentioned in
https://build.opensuse.org/request/show/265000 13.1 / openstack-dashboard
Comment 13 Swamp Workflow Management 2015-01-19 13:05:15 UTC
openSUSE-SU-2015:0078-1: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 852175,869696,871855,885588,891815,908199
CVE References: CVE-2013-6858,CVE-2014-0157,CVE-2014-3473,CVE-2014-3474,CVE-2014-3475,CVE-2014-3594,CVE-2014-8124
Sources used:
openSUSE 13.1 (src):    openstack-dashboard-2013.2.5.dev2.g9ee7273-4.1, python-django_openstack_auth-1.1.3-4.1