Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
OpenStack Horizon did not properly process Heat templates.
Software Description:
- horizon: Web interface for OpenStack cloud infrastructure
Details:
Cristian Fiorentino discovered that OpenStack Horizon did not properly
perform input sanitization for Heat templates. If a user were tricked into
using a specially crafted Heat template, an attacker could conduct
cross-site scripting attacks. With cross-site scripting vulnerabilities, if
a user were tricked into viewing server output during a crafted server
request, a remote attacker could exploit this to modify the contents, or
steal confidential data, within the same domain.
The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: openstack-dashboard 1:2013.2.3-0ubuntu1.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2206-1
CVE-2014-0157
Get the latest Linux and open source security news straight to your inbox.