6.8
CVSSv2

CVE-2012-2144

Published: 05/06/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote malicious users to hijack web sessions via the sessionid cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack horizon folsom-1

openstack horizon 2012.1

Vendor Advisories

Debian Bug report logs - #671604 [CVE-2012-2144] Horizon session fixation and reuse Package: horizon; Maintainer for horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Luciano Bello <luciano@debianorg> Date: Sat, 5 May 2012 09:54:15 UTC Severity: important Tags: patch, security Fixed in ...
Horizon could be made to expose sensitive information over the network ...