First published: Fri Jul 22 2022(Updated: )
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openstack | =16.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-1655.
The severity level of CVE-2022-1655 is medium.
Redhat Openstack version 16.2 is affected by CVE-2022-1655.
CVE-2022-1655 can lead to a loss of confidentiality and integrity.
To fix CVE-2022-1655, ensure that Horizon session cookies are created with the HttpOnly flag by setting HorizonSecureCookies to true in the environmental files.