Логотип exploitDog
bind:CVE-2019-10136
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-10136

Количество 4

Количество 4

redhat логотип

CVE-2019-10136

больше 6 лет назад

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2019-10136

больше 6 лет назад

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14163-1

больше 6 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий
github логотип

GHSA-w2m4-8m7f-6vwv

больше 3 лет назад

It was found that Spacewalk, all versions through 2.8, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2019-10136

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10136

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

CVSS3: 4.3
0%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:14163-1

Security update for SUSE Manager Client Tools

0%
Низкий
больше 6 лет назад
github логотип
GHSA-w2m4-8m7f-6vwv

It was found that Spacewalk, all versions through 2.8, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу