Bugzilla – Bug 933722
VUL-0: CVE-2015-3219: openstack-dashboard: XSS in Horizon Heat stack creation
Last modified: 2016-04-27 19:39:16 UTC
Created attachment 636852 [details] cve-2015-3219-stable-kilo.patch
Created attachment 636853 [details] cve-2015-3219-stable-juno.patch
Created attachment 636854 [details] cve-2015-3219-master-liberty.patch
An update workflow for this issue was started. This issue was rated as moderate. Please submit fixed packages until 2015-06-19. When done, reassign the bug to security-team@suse.de. https://swamp.suse.de/webswamp/wf/61888
bugbot adjusting priority
Public via https://security.openstack.org/ossa/OSSA-2015-010.html OSSA-2015-010: XSS in Horizon Heat stack creation Date: June 09, 2015 CVE: CVE-2015-3219 Affects: Horizon: 2014.2 versions through 2014.2.3 and version 2015.1.0 Description Nikita Konovalov from Mirantis reported a vulnerability in Horizon. By tricking a Horizon user into using a malicious template in the Orchestration/Stack section of Horizon, a remote attacker may trigger a cross-site-scripting vulnerability during the stack creation. It may result in potential assets theft like user access credentials. Only setups exposing the orchestration dashboard in Horizon are affected. Patches https://review.openstack.org/189821 (Juno) https://review.openstack.org/189822 (Kilo) https://review.openstack.org/189820 (Liberty) Credits Nikita Konovalov from Mirantis (CVE-2015-3219) References https://launchpad.net/bugs/1453074 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3219 Notes This fix will be included in future 2014.2.4 (juno) and 2015.1.1 (kilo) releases.
Submitted in mr#73509.
SUSE-SU-2015:2064-1: An update that solves two vulnerabilities and has 7 fixes is now available. Category: security (moderate) Bug References: 928891,931437,933607,933722,935442,936059,936368,945052,945515 CVE References: CVE-2015-3219,CVE-2015-3988 Sources used: SUSE OpenStack Cloud 5 (src): crowbar-barclamp-nova_dashboard-1.9+git.1443622531.b2b2939-9.3, openstack-dashboard-2014.2.4~a0~dev12-13.2, python-django_openstack_auth-1.1.7-11.3
released