CVE-2014-0090

Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
theforemanforeman
𝑥
≤ 1.4.1
theforemanforeman
1.0
theforemanforeman
1.1
theforemanforeman
1.2.0
theforemanforeman
1.2.0:rc1
theforemanforeman
1.2.0:rc2
theforemanforeman
1.2.1
theforemanforeman
1.2.2
theforemanforeman
1.2.3
theforemanforeman
1.4.0
𝑥
= Vulnerable software versions