Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-3852

Опубликовано: 21 окт. 2010
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5congaNot affected
Red Hat Enterprise Linux 6luciAffected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=626504Luci: Authentication bypass via fake ticket cookie

EPSS

Процентиль: 72%
0.00711
Низкий

4 Medium

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.

github
больше 3 лет назад

The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.

EPSS

Процентиль: 72%
0.00711
Низкий

4 Medium

CVSS2