Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-865x-x787-2cjj

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

EPSS

Процентиль: 35%
0.00142
Низкий

Связанные уязвимости

redhat
больше 12 лет назад

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

nvd
больше 11 лет назад

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

oracle-oval
больше 12 лет назад

ELSA-2013-0128: conga security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 35%
0.00142
Низкий