CVE-2022-1655
Last modified
CVE-2022-1655 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack | 16.2 |
References
- https://access.redhat.com/security/cve/cve-2022-1655Vendor Advisory
- https://access.redhat.com/security/cve/cve-2022-1655Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1655?
How severe is CVE-2022-1655?
How do I fix CVE-2022-1655?
Are you affected by CVE-2022-1655?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
