OpenStack / Horizon
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-55748 | OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters | MEDIUM | 6.0 | Jun 17, 2026 |
| CVE-2026-43002 | An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and t… | MEDIUM | 5.3 | May 5, 2026 |
| CVE-2022-45582 | Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. | MEDIUM | 5.3 | Aug 22, 2023 |
| CVE-2020-29565 | python-django-horizon: dashboard allows open redirect | MEDIUM | 5.3 | Dec 4, 2020 |
| CVE-2012-5474 | The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) i… | MEDIUM | 5.5 | Dec 30, 2019 |
| CVE-2012-5476 | Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin passwor… | MEDIUM | 5.5 | Dec 30, 2019 |
| CVE-2017-7400 | python-django-horizon: XSS in federation mappings UI | MEDIUM | 4.8 | Apr 3, 2017 |
| CVE-2016-4428 | python-django-horizon: XSS in client side template | MEDIUM | 5.4 | Jul 12, 2016 |
| CVE-2015-3219 | python-django-horizon: XSS in Heat stack creation | MEDIUM | 5.3 | Aug 20, 2015 |
| CVE-2015-3988 | python-django-horizon: persistent XSS in Horizon metadata dashboard | LOW | 3.5 | May 19, 2015 |
| CVE-2014-8124 | python-django-horizon: denial of service via login page requests | MEDIUM | 5.0 | Dec 12, 2014 |
| CVE-2014-8578 | openstack-horizon: multiple XSS flaws | LOW | 3.5 | Oct 31, 2014 |
| CVE-2014-3475 | openstack-horizon: multiple XSS flaws | LOW | 3.5 | Oct 31, 2014 |
| CVE-2014-3474 | openstack-horizon: multiple XSS flaws | LOW | 3.5 | Oct 31, 2014 |
| CVE-2014-3473 | openstack-horizon: multiple XSS flaws | MEDIUM | 4.3 | Oct 31, 2014 |
| CVE-2014-3594 | openstack-horizon: persistent XSS in Horizon Host Aggregates interface | LOW | 3.5 | Aug 22, 2014 |
| CVE-2013-4471 | OpenStack: python-django-horizonpassword reset vulnerability | MEDIUM | 5.5 | May 14, 2014 |
| CVE-2014-0157 | openstack-horizon: XSS in Horizon orchestration dashboard when using a malicious template | MEDIUM | 5.1 | Apr 15, 2014 |
| CVE-2013-6858 | openstack: horizon multiple XSS vulnerabilities. | MEDIUM | 4.3 | Nov 23, 2013 |
| CVE-2012-3542 | Keystone: Lack of authorization for adding users to tenants | HIGH | 8.7 | Sep 5, 2012 |
| CVE-2012-3540 | OpenStack-Horizon: Open redirect through 'next' parameter | MEDIUM | 5.8 | Sep 5, 2012 |
| CVE-2012-3426 | OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows… | MEDIUM | 4.9 | Jul 31, 2012 |
| CVE-2012-2144 | Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie. | MEDIUM | 6.8 | Jun 5, 2012 |
| CVE-2012-2094 | Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) fo… | MEDIUM | 4.3 | Jun 5, 2012 |
Showing 1 to 23 of 23 CVEs