Bug is now a public non-vulnerability, tagged as security hardening, no advisory. Thanks!
** Information type changed from Private Security to Public ** Tags added: security ** Changed in: ossa Status: Incomplete => Invalid -- You received this bug notification because you are a member of Yahoo! Engineering Team, which is subscribed to OpenStack Dashboard (Horizon). https://bugs.launchpad.net/bugs/1260525 Title: Incomplete XSS fix for ossa/1247675 Status in OpenStack Dashboard (Horizon): Confirmed Status in OpenStack Security Advisories: Invalid Bug description: The patch for https://bugs.launchpad.net/ossa/+bug/1247675 did not completely fix the reported issue. It failed to completely remove the use of html.strip_tags, which is not intended to be a security function, and does not properly sanitize output. https://github.com/openstack/horizon/blob/master/openstack_dashboard/dashboards/project/volumes/tables.py#L254 To manage notifications about this bug go to: https://bugs.launchpad.net/horizon/+bug/1260525/+subscriptions -- Mailing list: https://launchpad.net/~yahoo-eng-team Post to : yahoo-eng-team@lists.launchpad.net Unsubscribe : https://launchpad.net/~yahoo-eng-team More help : https://help.launchpad.net/ListHelp