{"id":"CVE-2014-0157","aliases":["GHSA-cmg8-5c63-pg95","PYSEC-2026-822"],"title":"OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting","summary":"OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting","severity":"medium","vendor":"horizon","product":"horizon","ecosystem":"pip","affected":["horizon >= 2013.2, < 2013.2.4"],"patched":["horizon 2013.2.4"],"published":"2022-05-14","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-cmg8-5c63-pg95","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0157"},{"url":"https://access.redhat.com/errata/RHSA-2014:0581"},{"url":"https://access.redhat.com/security/cve/CVE-2014-0157"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1082858"},{"url":"https://launchpad.net/bugs/1289033"},{"url":"https://opendev.org/openstack/horizon"},{"url":"https://web.archive.org/web/20200228185211/http://www.securityfocus.com/bid/66706"},{"url":"http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.html"},{"url":"http://www.openwall.com/lists/oss-security/2014/04/08/8"}],"tags":["osv","pip"],"epss":0.01216,"epssPercentile":0.66776,"ingestedAt":"2026-07-08T18:25:48.411Z","slug":"CVE-2014-0157","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.\n\n## Affected packages\n\n- `horizon >= 2013.2, < 2013.2.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `horizon 2013.2.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}