---
id: CVE-2017-7400
aliases:
  - GHSA-47vp-44v9-rhgq
  - PYSEC-2026-821
title: OpenStack Horizon Cross-site Scripting (XSS)
summary: OpenStack Horizon Cross-site Scripting (XSS)
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'
vendor: horizon
product: horizon
ecosystem: pip
affected:
  - 'horizon >= 9.0, < 9.1.2'
  - 'horizon >= 10.0, < 10.0.3'
  - 'horizon >= 11.0.0, < 11.0.1'
patched:
  - horizon 9.1.2
  - horizon 10.0.3
  - horizon 11.0.1
published: '2022-05-14'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-47vp-44v9-rhgq'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2017-7400'
  - url: 'https://access.redhat.com/errata/RHSA-2017:1598'
  - url: 'https://access.redhat.com/errata/RHSA-2017:1739'
  - url: 'https://launchpad.net/bugs/1667086'
  - url: >-
      https://opendev.org/openstack/horizon/commit/1407cfe53144146b29679de21f28c952282043ae
  - url: >-
      https://opendev.org/openstack/horizon/commit/511b325b45b6bd7a88bb6df1a4639b80d0121277
  - url: >-
      https://opendev.org/openstack/horizon/commit/a835dbfbaa2c70329c08d4b8429d49315dc6d651
  - url: >-
      https://opendev.org/openstack/horizon/commit/ce80bb6fec3cb0262728e7ae8b9d695cf832e5bf
  - url: 'http://www.securityfocus.com/bid/97324'
tags:
  - osv
  - pip
epss: 0.01063
epssPercentile: 0.63155
ingestedAt: '2026-07-08T18:25:45.281Z'
---

## Overview

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.

## Affected packages

- `horizon >= 9.0, < 9.1.2`
- `horizon >= 10.0, < 10.0.3`
- `horizon >= 11.0.0, < 11.0.1`

## Remediation

Upgrade to a patched release:

- `horizon 9.1.2`
- `horizon 10.0.3`
- `horizon 11.0.1`
