Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 492496 (CVE-2013-6858) - <www-apps/horizon-2013.1.4-r1: multiple XSS vulnerabilities (CVE-2013-6858)
Summary: <www-apps/horizon-2013.1.4-r1: multiple XSS vulnerabilities (CVE-2013-6858)
Status: RESOLVED FIXED
Alias: CVE-2013-6858
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-25 11:52 UTC by Agostino Sarubbo
Modified: 2014-02-17 06:47 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-11-25 11:52:21 UTC
From ${URL} :

Common Vulnerabilities and Exposures assigned an identifier CVE-2013-6858 to the following vulnerability:

Name: CVE-2013-6858
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6858
Assigned: 20131123
Reference: https://bugs.launchpad.net/horizon/+bug/1247675
Reference: SECUNIA:55770
Reference: http://secunia.com/advisories/55770

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier 
allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) 
"Network Topology" page.


@maintainer(s): since the package has never been marked as stable, we don't need to stabilize it. After the bump, please remove the affected versions from the tree.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2013-11-27 22:10:06 UTC
CVE-2013-6858 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6858):
  Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard
  (Horizon) 2013.2 and earlier allow local users to inject arbitrary web
  script or HTML via an instance name to (1) "Volumes" or (2) "Network
  Topology" page.
Comment 2 Matthew Thode ( prometheanfire ) archtester Gentoo Infrastructure gentoo-dev Security 2014-02-17 06:37:24 UTC
looks like I already fixed this in tree (horizon-2013.1.4-r1.ebuild)
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2014-02-17 06:47:39 UTC
Already Cleaned up... Thank you.

No GLSA needed as no stable versions available. Thank you for your work