CVE-2022-1655

Source
https://cve.org/CVERecord?id=CVE-2022-1655
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1655.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-1655
Downstream
Published
2022-07-22T15:15:08.057Z
Modified
2026-03-14T01:46:03.484194Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "16.2"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1655.json"