OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.
| Vendor | Product | Versions |
|---|---|---|
| openstack | skyline | 0, 6.0.0, 7.0.0 |
Updated severity to HIGH, noted no available exploit, and added new tag 'cross site scripting'.
Initial creation