VYPR
Moderate severityNVD Advisory· Published Apr 15, 2014· Updated May 6, 2026

CVE-2014-0157

CVE-2014-0157

Description

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
horizonPyPI
>= 2013.2, < 2013.2.42013.2.4

Affected products

5
  • OpenStack/Horizon4 versions
    cpe:2.3:a:openstack:horizon:2013.2:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:openstack:horizon:2013.2:*:*:*:*:*:*:*
    • cpe:2.3:a:openstack:horizon:2013.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:openstack:horizon:2013.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:openstack:horizon:2013.2.3:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.