CVE-2012-2144: Medium severity openstack horizon vulnerability
Published Jun 5, 2012
·Updated
Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.
Affected Software
3 affected componentsFixes available
Openstack Horizon=2012.1
Openstack Horizon=folsom-1
pip/horizon<8.0.0a0
8.0.0a0
Remediation
Event History
Jun 5, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·01:46 AM
Frequently Asked Questions
1
What is the severity of CVE-2012-2144?
CVE-2012-2144 is classified as a high severity vulnerability due to its potential for session hijacking.
2
How do I fix CVE-2012-2144?
To fix CVE-2012-2144, upgrade to Horizon version 8.0.0a0 or later.
3
Which versions are affected by CVE-2012-2144?
CVE-2012-2144 affects OpenStack Dashboard (Horizon) versions folsom-1 and 2012.1.
4
What type of vulnerability is CVE-2012-2144?
CVE-2012-2144 is a session fixation vulnerability.
5
Can CVE-2012-2144 be exploited remotely?
Yes, CVE-2012-2144 can be exploited remotely by attackers to hijack web sessions.