{"id":"CVE-2017-7400","details":"OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.","aliases":["GHSA-47vp-44v9-rhgq"],"modified":"2026-04-11T12:01:47.272344Z","published":"2017-04-03T14:59:00.167Z","related":["SUSE-SU-2017:1443-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"10.0.0-b1"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:10.0.0:b1:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"10.0.0-b2"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:10.0.0:b2:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"10.0.0-b3"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:10.0.0:b3:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"10.0.0-rc1"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:10.0.0:rc1:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"10.0.0-rc2"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:10.0.0:rc2:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"10.0.0-rc3"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:10.0.0:rc3:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"9.0.0-b1"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:9.0.0:b1:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"9.0.0-b2"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:9.0.0:b2:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"9.0.0-b3"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:9.0.0:b3:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"9.0.0-rc1"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:9.0.0:rc1:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"9.0.0-rc2"}],"source":"CPE_FIELD","cpe":"cpe:2.3:a:openstack:horizon:9.0.0:rc2:*:*:*:*:*:*"}]},"references":[{"type":"WEB","url":"https://launchpad.net/bugs/1667086"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/97324"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1598"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:1739"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openstack/horizon","events":[{"introduced":"0"},{"last_affected":"2eb320bd31078e3728b91e4badc597624d0827f8"},{"last_affected":"f4b9e17315c69749e6e84a518b385b3698d5ab0e"},{"last_affected":"8211d685afed20469b5bfd53c008e4bc98e7047a"},{"last_affected":"9a460aad76c05c411765af2b2d85b075a5f7004e"},{"last_affected":"f9b676aba63a55e61301dd4e4a1f58667b399e35"},{"last_affected":"ce5604c40663447227cbdf458b503fb32746279b"},{"last_affected":"72487730297c5182bb4478f980f23fdf58994341"},{"last_affected":"30d0a31d41340d0ad340d12db3455156b04e71fc"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"9.0.0"},{"last_affected":"9.0.1"},{"last_affected":"9.1.0"},{"last_affected":"9.1.1"},{"last_affected":"10.0.0"},{"last_affected":"10.0.1"},{"last_affected":"10.0.2"},{"last_affected":"11.0.0"}],"source":"CPE_FIELD","cpe":["cpe:2.3:a:openstack:horizon:9.0.0:*:*:*:*:*:*:*","cpe:2.3:a:openstack:horizon:9.0.1:*:*:*:*:*:*:*","cpe:2.3:a:openstack:horizon:9.1.0:*:*:*:*:*:*:*","cpe:2.3:a:openstack:horizon:9.1.1:*:*:*:*:*:*:*","cpe:2.3:a:openstack:horizon:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:openstack:horizon:10.0.1:*:*:*:*:*:*:*","cpe:2.3:a:openstack:horizon:10.0.2:*:*:*:*:*:*:*","cpe:2.3:a:openstack:horizon:11.0.0:*:*:*:*:*:*:*"]}}],"versions":["10.0.0","10.0.0.0b1","10.0.0.0b2","10.0.0.0b3","10.0.0.0rc1","10.0.0.0rc2","10.0.0.0rc3","10.0.1","10.0.2","11.0.0","11.0.0.0b1","11.0.0.0b2","11.0.0.0b3","11.0.0.0rc1","11.0.0.0rc2","2011.2","2013.1.g3","2013.1.rc1","2013.2.b1","2013.2.b2","2013.2.b3","2013.2.rc1","2014.1.b1","2014.1.b2","2014.1.b3","2014.1.rc1","2014.2.b1","2014.2.b2","2014.2.b3","2014.2.rc1","2015.1.0b1","2015.1.0b2","2015.1.0b3","2015.1.0rc1","8.0.0.0b1","8.0.0.0b2","8.0.0.0b3","8.0.0.0rc1","8.0.0a0","9.0.0","9.0.0.0b1","9.0.0.0b2","9.0.0.0b3","9.0.0.0rc1","9.0.0.0rc2","9.0.1","9.1.0","9.1.1","essex-1","essex-2","essex-3","folsom-2","folsom-3","grizzly-1","grizzly-2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-7400.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}