Vulnerabilities > Openstack > Horizon > 2012.1

DATE CVE VULNERABILITY TITLE RISK
2019-12-30 CVE-2012-5474 Missing Encryption of Sensitive Data vulnerability in multiple products
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
2.1
2014-10-31 CVE-2014-8578 Cross-Site Scripting vulnerability in Openstack Horizon
Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475.
network
openstack CWE-79
3.5
2012-06-05 CVE-2012-2144 Unspecified vulnerability in Openstack Horizon 2012.1/Folsom1
Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.
network
openstack
6.8
2012-06-05 CVE-2012-2094 Cross-Site Scripting vulnerability in Openstack Horizon 2012.1/Folsom1
Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.
network
openstack CWE-79
4.3