cbcvebase.
CVE-2012-2144
published 2012-06-05

CVE-2012-2144: Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.

PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.11%
79.8th percentile
Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianhorizon< horizon 2012.1-4 (bookworm)horizon 2012.1-4 (bookworm)
openstackhorizon
openstackhorizon
openstackhorizon>= 0 < 2012.1-42012.1-4
openstackhorizon>= 0 < 2012.1-42012.1-4
openstackhorizon>= 0 < 2012.1-42012.1-4
openstackhorizon>= 0 < 2012.1-42012.1-4
openstackhorizon>= 0 < 8.0.0a08.0.0a0

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.