Candidate: CVE-2016-6519 PublicDate: 2017-04-21 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6519 http://www.openwall.com/lists/oss-security/2016/09/15/7 https://github.com/openstack/manila-ui/blob/d5fe23e4ba30846acdd09fa1dc61a415016a7e26/manila_ui/dashboards/project/shares/shares/tabs.py#L49 Description: Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" form. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=838017 https://bugs.launchpad.net/manila-ui/+bug/1597738 https://bugzilla.suse.com/show_bug.cgi?id=988935 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [5.4 MEDIUM] Patches_manila-ui: upstream_manila-ui: needed precise_manila-ui: DNE precise/esm_manila-ui: DNE trusty_manila-ui: DNE trusty/esm_manila-ui: DNE vivid/stable-phone-overlay_manila-ui: DNE vivid/ubuntu-core_manila-ui: DNE xenial_manila-ui: ignored (end of standard support, was needed) yakkety_manila-ui: ignored (reached end-of-life) zesty_manila-ui: ignored (reached end-of-life) artful_manila-ui: ignored (reached end-of-life) bionic_manila-ui: not-affected (2.5.1-0) cosmic_manila-ui: not-affected (2.5.1-0) disco_manila-ui: not-affected (2.5.1-0) eoan_manila-ui: not-affected (2.5.1-0) focal_manila-ui: not-affected (2.5.1-0) groovy_manila-ui: not-affected (2.5.1-0) hirsute_manila-ui: not-affected (2.5.1-0) impish_manila-ui: not-affected (2.5.1-0) jammy_manila-ui: not-affected (2.5.1-0) devel_manila-ui: not-affected (2.5.1-0)