XSS The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
Bug #1940450 reported by
Heather Lemon
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Dashboard (Horizon) |
Invalid
|
Undecided
|
Unassigned | ||
OpenStack Security Advisory |
Invalid
|
Undecided
|
Unassigned | ||
Ubuntu Cloud Archive |
New
|
Undecided
|
Unassigned | ||
horizon (Ubuntu) |
Won't Fix
|
Undecided
|
Unassigned | ||
python-xstatic-bootstrap-scss (Ubuntu) |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
The data-template attribute of the tooltip and popover plugins lacks input sanitization and may allow attacker to execute arbitrary JavaScript.
github source: https:/
github upstream MR: https:/
ubuntu-cve https:/
openstack-
`pull-uca-source python-
CVE References
no longer affects: | ubuntu |
tags: | added: horizon-core |
tags: | added: cloud-archive |
Changed in horizon (Ubuntu): | |
status: | New → Won't Fix |
To post a comment you must log in.
Since this report concerns a possible security risk, an incomplete
security advisory task has been added while the core security
reviewers for the affected project or projects confirm the bug and
discuss the scope of any vulnerability along with potential
solutions.