CVE-2013-6858: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 1.7% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.

Affected products

  • Canonical Ubuntu Linux: version 12.10 only; version 13.04 only; version 13.10 only
  • Openstack Horizon: from 2013.1, up to and including 2013.2
  • Opensuse Opensuse: version 13.1 only

Published 2013-11-23. Last modified 2026-06-17.