CVE-2022-1655
Last modified
CVE-2022-1655 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack | 16.2 |
References
- https://access.redhat.com/security/cve/cve-2022-1655Vendor Advisory
- https://access.redhat.com/security/cve/cve-2022-1655Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1655?
How severe is CVE-2022-1655?
How do I fix CVE-2022-1655?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-1649Null pointer dereference in libr/bin/format/mach0/mach0.c in…5.5
- CVE-2022-1650Improper Removal of Sensitive Information Before Storage or …9.3
- CVE-2022-1651A memory leak flaw was found in the Linux kernel in acrn_dev…7.1
- CVE-2022-1652Linux Kernel could allow a local attacker to execute arbitra…7.8
- CVE-2022-1653The Social Share Buttons by Supsystic WordPress plugin befor…4.3
- CVE-2022-1654Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 al…8.8
- CVE-2022-1656Vulnerable versions of the JupiterX Theme (<=2.0.6) allow an…5.4
- CVE-2022-1657Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX …8.8
- CVE-2022-1658Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow a…5.4
- CVE-2022-1659Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin r…7.3
- CVE-2022-1660The affected products are vulnerable of untrusted data due t…9.8
- CVE-2022-1661The affected products are vulnerable to directory traversal,…7.5
Are you affected by CVE-2022-1655?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
