OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
{
"binaries": [
{
"binary_version": "2:9.1.2-0ubuntu1",
"binary_name": "openstack-dashboard"
},
{
"binary_version": "2:9.1.2-0ubuntu1",
"binary_name": "openstack-dashboard-ubuntu-theme"
},
{
"binary_version": "2:9.1.2-0ubuntu1",
"binary_name": "python-django-horizon"
}
],
"availability": "No subscription required"
}