CVE-2016-6519
Summary
| CVE | CVE-2016-6519 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-21 15:59:00 UTC |
| Updated | 2023-11-07 02:34:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Manila | All | All | All | All |
| Application | Redhat | Openstack | 7.0 | All | All | All |
| Application | Redhat | Openstack | 8 | All | All | All |
| Application | Redhat | Openstack | 8.0 | All | All | All |
| Application | Redhat | Openstack | 9 | All | All | All |
| Application | Redhat | Openstack | 9.0 | All | All | All |
| Application | Redhat | Openstack | 7.0 | All | All | All |
| Application | Redhat | Openstack | 8.0 | All | All | All |
| Application | Redhat | Openstack | 9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Third Party Advisory |
| oss-security - CVE-2016-6519: openstack-manila: Persistent XSS in Metadata field | www.openwall.com | ||
| 1375147 – (CVE-2016-6519) CVE-2016-6519 openstack-manila-ui: persistent XSS in metadata field | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Third Party Advisory |
| Bug #1597738 “Persistent XSS in Metadata field” : Bugs : manila-ui | CONFIRM | bugs.launchpad.net | Issue Tracking, Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | rhn.redhat.com | ||
| OpenStack manila CVE-2016-6519 HTML Injection Vulnerability | www.securityfocus.com | ||
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.