Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-5014

Опубликовано: 06 нояб. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authorization cookie, a related issue to CVE-2010-3852.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.0.3-2
hardy

DNE

karmic

not-affected

2.0.3-1
lucid

not-affected

2.0.3-1
maverick

not-affected

2.0.3-2
upstream

released

2.0.2

Показывать по

Ссылки на источники

EPSS

Процентиль: 53%
0.00304
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
около 15 лет назад

The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authorization cookie, a related issue to CVE-2010-3852.

debian
около 15 лет назад

The default quickstart configuration of TurboGears2 (aka tg2) before 2 ...

github
больше 3 лет назад

The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authorization cookie, a related issue to CVE-2010-3852.

EPSS

Процентиль: 53%
0.00304
Низкий

7.5 High

CVSS2