Bug 2075681 (CVE-2022-1655)
Summary: | CVE-2022-1655 OpenStack: Horizon session cookies are not flagged HttpOnly | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sage McTaggart <amctagga> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | eglynn, jjoyce, lhh, mburns, rdopiera, rhos-maint, spower, steve.beattie |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | OpenStack 16.2 | Doc Type: | If docs needed, set a value |
Doc Text: |
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2022-12-09 22:13:58 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2083840 | ||
Bug Blocks: | 2075679 |
Description
Sage McTaggart
2022-04-14 21:25:38 UTC
This issue has been addressed in the following products: Red Hat OpenStack Platform 16.2 Via RHSA-2022:8856 https://access.redhat.com/errata/RHSA-2022:8856 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-1655 |