Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
OpenStack Dashboard (Horizon) provides administrators and users with a
graphical interface to access, provision, and automate cloud-based
resources.
The following packages have been upgraded to a newer upstream version:
python-django-horizon: 2015.1.4 (BZ#1345822)
Security Fix(es):
* A DOM-based, cross-site scripting vulnerability was found in the
OpenStack dashboard, where user input was not filtered correctly. An
authenticated dashboard user could exploit the flaw by injecting an
AngularJS template into a dashboard form (for example, using an image's
description), triggering the vulnerability when another user browsed
the affected page. As a result, this flaw could result in user accounts
being compromised (for example, user-access credentials being stolen).
(CVE-2016-4428)
Red Hat would like to thank the OpenStack project for reporting this issue.
Upstream acknowledges Beth Lancaster (Virginia Tech) and Brandon Sawyers(Virginia Tech) as the original reporters.
https://access.redhat.com/security/cve/CVE-2016-4428 https://access.redhat.com/security/updates/classification#important
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7:
Source:
python-django-horizon-2015.1.4-1.el7ost.src.rpm
noarch:
openstack-dashboard-2015.1.4-1.el7ost.noarch.rpm
openstack-dashboard-theme-2015.1.4-1.el7ost.noarch.rpm
python-django-horizon-2015.1.4-1.el7ost.noarch.rpm
python-django-horizon-doc-2015.1.4-1.el7ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key
An update for python-django-horizon is now available for Red HatEnterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7.Red Hat Product Security has rated this update as having a securityimpact of Important. A Common Vulnerability Scoring System (CVSS) basescore, which gives a detailed severity rating, is available for eachvulnerability from the CVE link(s) in the References section.
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 - noarch
1287881 - Heat UI objects are not displayed in the UI
1343982 - CVE-2016-4428 python-django-horizon: XSS in client side template
Get the latest Linux and open source security news straight to your inbox.