ossa/ossa/OSSA-2012-006.yaml

56 lines
1.1 KiB
YAML

date: 2012-05-04
id: OSSA-2012-006
title: 'Horizon session fixation and reuse'
description: 'Thomas Biege from SUSE reported a vulnerability in OpenStack Dashboard
(Horizon). Under specific circumstances it is possible to reuse session cookies
from another user, potentially allowing access to unauthorized information and capabilities. '
reference: https://lists.launchpad.net/openstack/msg11263.html
affected-products:
- product: horizon
version: All versions
vulnerabilities:
- cve-id: CVE-2012-2144
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 5.8
detail: AV:N/AC:M/Au:N/C:P/I:P/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Thomas Biege'
affiliation: SUSE
reported:
- CVE-2012-2144
issues:
links:
- https://launchpad.net/bugs/978896
type: launchpad
reviews:
folsom:
- https://review.openstack.org/#/c/7144
essex:
- https://review.openstack.org/#/c/7145
type: gerrit