CVE-2019-10136
02.07.2019, 20:15
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | satellite | 5.8 |
redhat | spacewalk | 𝑥 ≤ 2.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration