Количество 4
Количество 4
CVE-2019-10136
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.
CVE-2019-10136
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.
SUSE-SU-2019:14163-1
Security update for SUSE Manager Client Tools
GHSA-w2m4-8m7f-6vwv
It was found that Spacewalk, all versions through 2.8, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-10136 It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum. | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад | |
CVE-2019-10136 It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum. | CVSS3: 4.3 | 0% Низкий | больше 6 лет назад | |
SUSE-SU-2019:14163-1 Security update for SUSE Manager Client Tools | 0% Низкий | больше 6 лет назад | ||
GHSA-w2m4-8m7f-6vwv It was found that Spacewalk, all versions through 2.8, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу