VYPR

Horizon

by OpenStack

pypi: horizon

Source repositories

CVEs (23)

  • CVE-2012-3426Jul 31, 2012
    risk 0.00cvss —epss 0.02

    OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token…

  • CVE-2012-2144Jun 5, 2012
    risk 0.00cvss —epss 0.02

    Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.

  • CVE-2012-2094Jun 5, 2012
    risk 0.00cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.

Page 2 of 2