CVE-2012-2144
published 2012-06-05CVE-2012-2144: Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.11%
79.8th percentile
Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 2012.1-4 (bookworm) | horizon 2012.1-4 (bookworm) |
| openstack | horizon | — | — |
| openstack | horizon | — | — |
| openstack | horizon | >= 0 < 2012.1-4 | 2012.1-4 |
| openstack | horizon | >= 0 < 2012.1-4 | 2012.1-4 |
| openstack | horizon | >= 0 < 2012.1-4 | 2012.1-4 |
| openstack | horizon | >= 0 < 2012.1-4 | 2012.1-4 |
| openstack | horizon | >= 0 < 8.0.0a0 | 8.0.0a0 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Horizon Session Fixation
ghsa·2022-05-17
CVE-2012-2144 [MEDIUM] CWE-384 OpenStack Horizon Session Fixation
OpenStack Horizon Session Fixation
Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.
OSV
OpenStack Horizon Session Fixation
osv·2022-05-17
CVE-2012-2144 [MEDIUM] OpenStack Horizon Session Fixation
OpenStack Horizon Session Fixation
Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.
OSV
CVE-2012-2144: Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012
osv·2012-06-05·CVSS 6.8
CVE-2012-2144 [MEDIUM] CVE-2012-2144: Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012
Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.
Ubuntu
Horizon vulnerabilities
vendor_ubuntu·2012-05-07·CVSS 4.3
CVE-2012-2094 [MEDIUM] Horizon vulnerabilities
Title: Horizon vulnerabilities
Summary: Horizon could be made to expose sensitive information over the network.
Matthias Weckbecker discovered a cross-site scripting (XSS) vulnerability
in Horizon via the log viewer refrash mechanism. If a user were tricked
into viewing a specially crafted log message, a remote attacker could
exploit this to modify the contents or steal confidential data within the
same domain. (CVE-2012-2094)
Thomas Biege discovered a session fixation vulnerability in Horizon. An
attacker could exploit this to potentially allow access to unauthorized
information and capabilities. (CVE-2012-2144)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-2144: horizon - Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 201...
vendor_debian·2012·CVSS 6.8
CVE-2012-2144 [MEDIUM] CVE-2012-2144: horizon - Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 201...
Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.
Scope: local
bookworm: resolved (fixed in 2012.1-4)
bullseye: resolved (fixed in 2012.1-4)
forky: resolved (fixed in 2012.1-4)
sid: resolved (fixed in 2012.1-4)
trixie: resolved (fixed in 2012.1-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse [epel-6]
bugzilla·2012-05-03·CVSS 6.8
CVE-2012-2144 [MEDIUM] CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse [epel-6]
CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=sec
Bugzilla
CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse [fedora-17]
bugzilla·2012-05-03·CVSS 6.8
CVE-2012-2144 [MEDIUM] CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse [fedora-17]
CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse [fedora-17]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=
Bugzilla
CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse
bugzilla·2012-04-27·CVSS 6.8
CVE-2012-2144 [MEDIUM] CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse
CVE-2012-2144 python-django-horizon: Horizon session fixation and reuse
Thomas Biege from SUSE reported a vulnerability in the OpenStack Dashboard (Horizon). Under certain specific circumstances, it was possible to reuse session cookies from another user, possibly allowing access to unauthorized information and capabilities.
Discussion:
Created python-django-horizon tracking bugs for this issue
Affects: fedora-17 [bug 818680]
Affects: epel-6 [bug 818681]
---
This has been fixed in python-django-horizon-2012.1-4.el6 (EPEL6) and python-django-horizon-2012.1-3.fc17 (Fedora 17).
http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081173.htmlhttp://secunia.com/advisories/49024http://secunia.com/advisories/49071http://ubuntu.com/usn/usn-1439-1http://www.openwall.com/lists/oss-security/2012/05/05/1http://www.osvdb.org/81741http://www.securityfocus.com/bid/53399https://bugs.launchpad.net/horizon/+bug/978896https://exchange.xforce.ibmcloud.com/vulnerabilities/75423https://github.com/openstack/horizon/commit/041b1c44c7d6cf5429505067c32f8f35166a8babhttp://lists.fedoraproject.org/pipermail/package-announce/2012-May/081173.htmlhttp://secunia.com/advisories/49024http://secunia.com/advisories/49071http://ubuntu.com/usn/usn-1439-1http://www.openwall.com/lists/oss-security/2012/05/05/1http://www.osvdb.org/81741http://www.securityfocus.com/bid/53399https://bugs.launchpad.net/horizon/+bug/978896https://exchange.xforce.ibmcloud.com/vulnerabilities/75423https://github.com/openstack/horizon/commit/041b1c44c7d6cf5429505067c32f8f35166a8bab
2012-06-05
Published