PT-2012-6309 · Openstack · Openstack Dashboard

Published

2012-06-05

·

Updated

2012-06-05

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions OpenStack Dashboard (Horizon) versions folsom-1 through 2012.1
Description A session fixation issue allows remote attackers to hijack web sessions via the sessionid cookie.
Recommendations For OpenStack Dashboard (Horizon) versions folsom-1 through 2012.1, consider regenerating session IDs upon user login to prevent session fixation attacks. As a temporary workaround, restrict access to sensitive operations that rely on session authentication until a patch is available.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2012-33

Affected Products

Openstack Dashboard