PT-2012-6309 · Openstack · Openstack Dashboard
Published
2012-06-05
·
Updated
2012-06-05
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
OpenStack Dashboard (Horizon) versions folsom-1 through 2012.1
Description
A session fixation issue allows remote attackers to hijack web sessions via the
sessionid cookie.Recommendations
For OpenStack Dashboard (Horizon) versions folsom-1 through 2012.1, consider regenerating session IDs upon user login to prevent session fixation attacks. As a temporary workaround, restrict access to sensitive operations that rely on session authentication until a patch is available.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openstack Dashboard