📦

horizon

Vendor: openstack

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 2 Remote Access
Total CVEs 82 Total Indexed
Avg. EPSS 1.21% Exploit Prob.
Latest CVE CVE-2023-40314 Nov 16

Security Vulnerability Index

Page 6 / 9
4.3 CVSS

Cross-site scripting (XSS) vulnerability in the refresh mechanism in the log viewer in horizon/static/horizon/js/horizon.js in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the guest console.

EPSS: 2.42%