CVE-2022-1655
published 2022-07-22CVE-2022-1655: An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.47%
37.5th percentile
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenStack: Horizon session cookies are not flagged HttpOnly
vendor_redhat·2022-04-14·CVSS 6.5
CVE-2022-1655 [MEDIUM] CWE-732 OpenStack: Horizon session cookies are not flagged HttpOnly
OpenStack: Horizon session cookies are not flagged HttpOnly
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Debian
CVE-2022-1655: horizon - An Incorrect Permission Assignment for Critical Resource flaw was found in Horiz...
vendor_debian·2022·CVSS 6.5
CVE-2022-1655 [MEDIUM] CVE-2022-1655: horizon - An Incorrect Permission Assignment for Critical Resource flaw was found in Horiz...
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-xm48-7qq2-36x4: An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack
ghsa_unreviewed·2022-07-23
CVE-2022-1655 [MEDIUM] CWE-732 GHSA-xm48-7qq2-36x4: An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-22
Published