CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. See the original NVD description below for full technical details.
CVE
CVE-2022-1655
Severity
MEDIUM
CVSS
6.5
EPSS
0.52%
Original NVD Description
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
Related CVEs
Other vulnerabilities affecting the same vendor(s)