Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10136

Опубликовано: 02 июл. 2019
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:satellite:5.8:*:*:*:*:*:*:*
cpe:2.3:a:redhat:spacewalk:*:*:*:*:*:*:*:*
Версия до 2.9 (включая)

EPSS

Процентиль: 28%
0.00102
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-347
CWE-347

Связанные уязвимости

CVSS3: 4.3
redhat
больше 6 лет назад

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

suse-cvrf
больше 6 лет назад

Security update for SUSE Manager Client Tools

CVSS3: 4.3
github
больше 3 лет назад

It was found that Spacewalk, all versions through 2.8, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

EPSS

Процентиль: 28%
0.00102
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-347
CWE-347