CVE-2012-2094: OpenStack Horizon Cross-site scripting (XSS) vulnerability
(updated )
Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js
in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.
References
- bugs.launchpad.net/horizon/+bug/977944
- exchange.xforce.ibmcloud.com/vulnerabilities/76136
- github.com/advisories/GHSA-j772-hpmw-32rm
- github.com/openstack/horizon/commit/7f8c788aa70db98ac904f37fa4197fcabb802942
- github.com/openstack/horizon/commit/ab2e27522aaeb0268fcc121bd3eff5a4485f313c
- github.com/pypa/advisory-database/tree/main/vulns/horizon/PYSEC-2012-32.yaml
- lists.launchpad.net/openstack/msg10211.html
- nvd.nist.gov/vuln/detail/CVE-2012-2094
Detect and mitigate CVE-2012-2094 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →