OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| horizon(PyPI) | 9.0 | 9.1.2 | N/A |
| horizon(PyPI) | 10.0 | 10.0.3 | N/A |
| horizon(PyPI) | 11.0.0 | 11.0.1 | N/A |
CVSS Metrics