Bugzilla – Bug 903666
VUL-0: CVE-2014-8578: openstack-dashboard: Cross-site scripting (XSS) vulnerability in the Groups panel
Last modified: 2014-11-13 12:52:47 UTC
Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8578 http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-8578.html http://www.cvedetails.com/cve/CVE-2014-8578/
bugbot adjusting priority
looks like we already have this fix included.