affected: - package: ecosystem: PyPI name: horizon purl: pkg:pypi/horizon ranges: - events: - introduced: '0' - fixed: 041b1c44c7d6cf5429505067c32f8f35166a8bab repo: https://github.com/openstack/horizon type: GIT - events: - introduced: '0' type: ECOSYSTEM versions: - 12.0.2 - 12.0.3 - 12.0.4 - 13.0.0 - 13.0.0.0b3 - 13.0.0.0rc1 - 13.0.0.0rc2 - 13.0.1 - 13.0.2 - 13.0.3 - 14.0.0 - 14.0.0.0b1 - 14.0.0.0b2 - 14.0.0.0b3 - 14.0.0.0rc1 - 14.0.0.0rc2 - 14.0.1 - 14.0.2 - 14.0.3 - 14.0.4 - 14.1.0 - 15.0.0 - 15.0.0.0b1 - 15.0.0.0b2 - 15.0.0.0rc1 - 15.0.0.0rc2 - 15.1.0 - 15.1.1 - 15.2.0 - 15.3.0 - 15.3.1 - 15.3.2 - 16.0.0 - 16.0.0.0b1 - 16.0.0.0b2 - 16.0.0.0rc1 - 16.0.0.0rc2 - 16.1.0 - 16.2.0 - 16.2.1 - 16.2.2 - 17.0.0 - 17.1.0 - 18.0.0 - 18.1.0 - 18.2.0 - 18.3.0 - 18.3.1 - 18.3.2 - 18.3.3 - 18.3.4 - 18.3.5 - 18.4.0 - 18.4.1 - 18.5.0 - 18.6.0 - 18.6.1 - 18.6.2 - 18.6.3 - 18.6.4 - 19.0.0 - 19.1.0 - 19.2.0 - 19.3.0 - 19.4.0 - 20.0.0 - 20.1.0 - 20.1.1 - 20.1.2 - 20.1.3 - 20.1.4 - 20.2.0 - 21.0.0 - 22.0.0 - 22.1.0 - 22.1.1 - 22.2.0 - 23.0.0 - 23.0.1 - 23.0.2 - 23.1.0 - 23.1.1 - 23.2.0 - 23.3.0 - 23.4.0 - 24.0.0 - 25.0.0 - 25.1.0 - 23.3.1 - 24.0.1 - 24.0.2 - 25.1.1 - 25.1.2 - 25.2.0 - 25.3.0 - 25.3.1 - 25.3.2 - 25.4.0 - 25.5.0 - 25.5.1 - 25.5.2 - 25.6.0 - 25.7.0 - 25.7.1 - 25.7.2 - 25.7.3 aliases: - CVE-2012-2144 - GHSA-w7h9-8wr4-hwqh details: Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie. id: PYSEC-2012-33 modified: '2026-06-10T16:51:25.267147Z' published: '2012-06-05T22:55:00Z' references: - type: WEB url: http://www.securityfocus.com/bid/53399 - type: EVIDENCE url: https://github.com/openstack/horizon/commit/041b1c44c7d6cf5429505067c32f8f35166a8bab - type: FIX url: https://github.com/openstack/horizon/commit/041b1c44c7d6cf5429505067c32f8f35166a8bab - type: ADVISORY url: http://secunia.com/advisories/49024 - type: WEB url: http://www.openwall.com/lists/oss-security/2012/05/05/1 - type: ADVISORY url: http://secunia.com/advisories/49071 - type: WEB url: http://ubuntu.com/usn/usn-1439-1 - type: WEB url: http://lists.fedoraproject.org/pipermail/package-announce/2012-May/081173.html - type: WEB url: https://bugs.launchpad.net/horizon/+bug/978896 - type: WEB url: http://www.osvdb.org/81741 - type: WEB url: https://exchange.xforce.ibmcloud.com/vulnerabilities/75423 - type: ADVISORY url: https://github.com/advisories/GHSA-w7h9-8wr4-hwqh withdrawn: '2024-11-22T04:37:04Z'