CVE-2010-3852
06.11.2010, 00:00
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | luci | 𝑥 ≤ 0.22.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References