Vulnerabilities > Openstack > Horizon > 2012.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-12-30 | CVE-2012-5474 | Missing Encryption of Sensitive Data vulnerability in multiple products The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. | 2.1 |
2014-10-31 | CVE-2014-8578 | Cross-Site Scripting vulnerability in Openstack Horizon Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475. | 3.5 |
2012-06-05 | CVE-2012-2144 | Unspecified vulnerability in Openstack Horizon 2012.1/Folsom1 Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie. network openstack | 6.8 |
2012-06-05 | CVE-2012-2094 | Cross-Site Scripting vulnerability in Openstack Horizon 2012.1/Folsom1 Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console. | 4.3 |