Horizon

Latest version: v25.1.0

Vulnerabilities (21)

CVE/PVE Vulnerability ID Advisory Affected versions Severity Severity Score
CVE-2022-45582 60627

Horizon 19.4.0, 20.1.4, 22.1.1 and 23.1.0 include a fix for an Open R…

  • <19.4.0
  • >=20.0.0,<21.1.4
  • >=22.0.0,<22.1.1
  • ==23.0.0
MEDIUM 6.1
CVE-2017-7400 67543

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 …

  • >=9.0.0,<=9.1.1
  • >=10.0.0,<=10.0.2
  • ==11.0.0
MEDIUM 4.8
CVE-2014-3474 70775

Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js…

  • ==2014.2
  • >=2013.2,<2013.2.4
  • >=2014.1,<2014.1.2
LOW 3.5
CVE-2014-3473 70774

Cross-site scripting (XSS) vulnerability in the Orchestration/Stack s…

  • ==2014.2
  • >=2013.2,<2013.2.4
  • >=2014.1,<2014.1.2
MEDIUM 4.3
CVE-2020-29565 39226

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x befo…

  • <15.3.2
  • >=17.0,<18.3.3
  • >=16.0.0.0b1,<16.2.1
MEDIUM 6.1
CVE-2016-4428 70766

Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Hori…

  • >=9.0.0,<=9.0.1
  • >=8.0.0,<=8.0.1
MEDIUM 5.4
CVE-2015-3219 70418

Cross-site scripting (XSS) vulnerability in the Orchestration/Stack s…

  • >2014.2,<2014.2.4
  • >2015.1,<2015.1.1
MEDIUM 4.3
CVE-2014-8124 70611

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 201…

  • >=2010,<2014.1.3
  • >=2014.2.0,<2014.2.1
MEDIUM 5.0
CVE-2014-8578 70584

Cross-site scripting (XSS) vulnerability in the Groups panel in OpenS…

  • >2010,<2013.2.4
  • >=2014.1,<2014.2
LOW 3.5
CVE-2014-3475 70423

Cross-site scripting (XSS) vulnerability in the Users panel (admin/us…

  • >2010,<2013.2.4
  • >=2014.1,<2014.1.2
LOW 3.5
CVE-2014-3594 70590

Cross-site scripting (XSS) vulnerability in the Host Aggregates inter…

  • >=2010,<2013.2.4
  • >=2014.1,<2014.1.2
LOW 3.5
CVE-2022-1655 50264

Horizon 22.2.0 and prior versions are affected by CVE-2022-1655: An I…

  • <=22.2.0
MEDIUM 6.5
CVE-2014-0157 35505

Cross-site scripting (XSS) vulnerability in the Horizon Orchestration…

  • >=2013.2.0,<2013.2.4
MEDIUM 4.3
CVE-2013-4471 60961

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 do…

  • >=2013.1,<2013.2
MEDIUM 5.5
CVE-2012-5476 67991

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard pac…

  • >=2012.2,<=2012.2
MEDIUM 5.5
CVE-2012-2144 68012

Session fixation vulnerability in OpenStack Dashboard (Horizon) folso…

  • >=2012,<2012.1.1
MEDIUM 6.8
CVE-2015-3988 70417

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dash…

  • >2010,<2015.1.1
LOW 3.5
CVE-2013-6858 70589

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dash…

  • >2010,<2013.2.1
MEDIUM 4.3
CVE-2012-5474 37741

Horizon 2012.1.1 includes a fix for CVE-2012-5474: The file /etc/open…

  • >2010,<2012.1.1
MEDIUM 5.5
CVE-2012-2094 68011

Cross-site scripting (XSS) vulnerability in the refresh mechanism in …

  • >2010,<=2012.1
MEDIUM 4.3
CVE-2012-3540 68014

Open redirect vulnerability in views/auth_forms.py in OpenStack Dashb…

  • >2010,<=2012.1
MEDIUM 5.8