OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "openstack-dashboard", "binary_version": "2:9.1.2-0ubuntu1" }, { "binary_name": "openstack-dashboard-ubuntu-theme", "binary_version": "2:9.1.2-0ubuntu1" }, { "binary_name": "python-django-horizon", "binary_version": "2:9.1.2-0ubuntu1" } ], "ubuntu_priority": "negligible" }