Moderate severityNVD Advisory· Published Apr 15, 2014· Updated May 6, 2026
CVE-2014-0157
CVE-2014-0157
Description
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
horizonPyPI | >= 2013.2, < 2013.2.4 | 2013.2.4 |
Affected products
5Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- www.openwall.com/lists/oss-security/2014/04/08/8nvdPatchWEB
- github.com/advisories/GHSA-cmg8-5c63-pg95ghsaADVISORY
- launchpad.net/bugs/1289033nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2014-0157ghsaADVISORY
- lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlnvdWEB
- access.redhat.com/errata/RHSA-2014:0581ghsaWEB
- access.redhat.com/security/cve/CVE-2014-0157ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- opendev.org/openstack/horizonghsaPACKAGE
- web.archive.org/web/20200228185211/http://www.securityfocus.com/bid/66706ghsaWEB
- www.securityfocus.com/bid/66706nvd
News mentions
0No linked articles in our index yet.