{"id":"CVE-2014-3594","aliases":["GHSA-8g68-2hcj-h8vg","PYSEC-2026-641"],"title":"OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface","summary":"OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface","severity":"low","vendor":"horizon","product":"horizon","ecosystem":"pip","affected":["horizon < 8.0.0a0"],"patched":["horizon 8.0.0a0"],"published":"2022-05-13","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8g68-2hcj-h8vg","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3594"},{"url":"https://github.com/openstack/horizon/commit/ba2c98aea0db0d03200c811b86b3efe8367f3905"},{"url":"https://github.com/openstack/horizon/commit/ba908ae88d5925f4f6783eb234cc4ea95017472b"},{"url":"https://access.redhat.com/errata/RHSA-2014:1188"},{"url":"https://access.redhat.com/errata/RHSA-2014:1335"},{"url":"https://access.redhat.com/errata/RHSA-2014:1336"},{"url":"https://access.redhat.com/security/cve/CVE-2014-3594"},{"url":"https://bugs.launchpad.net/horizon/+bug/1349491"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1129774"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95378"},{"url":"https://review.openstack.org/#/c/115310"},{"url":"https://review.openstack.org/#/c/115311"},{"url":"https://review.openstack.org/#/c/115313"},{"url":"http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1335.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1336.html"},{"url":"http://seclists.org/oss-sec/2014/q3/413"},{"url":"http://www.securityfocus.com/bid/69291"}],"tags":["osv","pip"],"epss":0.0207,"epssPercentile":0.80318,"ingestedAt":"2026-07-08T18:25:47.481Z","slug":"CVE-2014-3594","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.\n\n## Affected packages\n\n- `horizon < 8.0.0a0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `horizon 8.0.0a0`","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}