Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qq64-jrrc-67ww

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.

WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.

EPSS

Процентиль: 35%
0.00144
Низкий

Связанные уязвимости

nvd
больше 15 лет назад

WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.

EPSS

Процентиль: 35%
0.00144
Низкий