Описание
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | piranha | Affected | ||
Red Hat Enterprise Linux 5 | piranha | Fixed | RHSA-2014:0174 | 13.02.2014 |
Red Hat Enterprise Linux 6 | piranha | Fixed | RHSA-2014:0175 | 13.02.2014 |
Показывать по
10
Дополнительная информация
Статус:
Important
https://bugzilla.redhat.com/show_bug.cgi?id=1043040piranha: web UI authentication bypass using POST requests
EPSS
Процентиль: 86%
0.02954
Низкий
5.8 Medium
CVSS2
Связанные уязвимости
nvd
больше 11 лет назад
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.
github
больше 3 лет назад
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.
EPSS
Процентиль: 86%
0.02954
Низкий
5.8 Medium
CVSS2