NA

CVE-2022-1655

Published: 22/07/2022 Updated: 29/07/2022
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openstack 16.2

Vendor Advisories

Synopsis Low: Red Hat OpenStack Platform 1624 (python-django-horizon) security update Type/Severity Security Advisory: Low Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for python-django-horizon is now available for Red Hat OpenStackPlatform 1624 ( ...