CVE-2013-6858

NameCVE-2013-6858
DescriptionMultiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitylow (attack range: local)
Debian Bugs730752

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
horizon (PTS)wheezy2012.1.1-10fixed
wheezy (security)2012.1.1-10+deb7u1fixed
jessie (security), jessie2014.1.3-7+deb8u2fixed
stretch3:10.0.1-1fixed
buster, sid3:12.0.0-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
horizonsource(unstable)2013.2-2low730752
horizonsourcewheezy(not affected)

Notes

[wheezy] - horizon <not-affected> (Vulnerable code not present)
https://github.com/openstack/horizon/commit/6179f70290783e55b10bbd4b3b7ee74db3f8ef70

Search for package or bug name: Reporting problems