CVE-2022-1655: Medium severity red hat openstack for ibm power vulnerability
Published Jul 22, 2022
·Updated
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Affected Software
1 affected component
redhat Openstack=16.2
Event History
Jul 22, 2022
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this flaw?
The vulnerability ID is CVE-2022-1655.
2
What is the severity level of CVE-2022-1655?
The severity level of CVE-2022-1655 is medium.
3
What software is affected by CVE-2022-1655?
Redhat Openstack version 16.2 is affected by CVE-2022-1655.
4
What is the impact of CVE-2022-1655?
CVE-2022-1655 can lead to a loss of confidentiality and integrity.
5
How can I fix CVE-2022-1655?
To fix CVE-2022-1655, ensure that Horizon session cookies are created with the HttpOnly flag by setting HorizonSecureCookies to true in the environmental files.