VDB
Sign up

PYSEC-2012-33

Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.

Quick fix

PYSEC-2012-33 — horizon: upgrade to the fixed version with the command below.

pip install --upgrade 'horizon>=041b1c44c7d6cf5429505067c32f8f35166a8bab'

Details

Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid cookie.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/horizon
Introduced in: 0Fixed in: 041b1c44c7d6cf5429505067c32f8f35166a8bab
Fixpip install --upgrade 'horizon>=041b1c44c7d6cf5429505067c32f8f35166a8bab'

References