Описание
cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- PatchVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:cosign:cosign:0.7.0:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:0.8.0:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:0.9.0:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:1.0:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:1.1:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:1.5:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:1.6:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:1.7:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:1.8:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:1.9:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cosign:cosign:2.0.2:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05055
Низкий
6.5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
EPSS
Процентиль: 90%
0.05055
Низкий
6.5 Medium
CVSS2
Дефекты
NVD-CWE-Other