CVE Vulnerabilities

CVE-2007-2233

Published: Apr 25, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.

Affected Software

NameVendorStart VersionEnd Version
CosignCosign0.7.0 (including)0.7.0 (including)
CosignCosign0.8.0 (including)0.8.0 (including)
CosignCosign0.9.0 (including)0.9.0 (including)
CosignCosign1.0 (including)1.0 (including)
CosignCosign1.1 (including)1.1 (including)
CosignCosign1.5 (including)1.5 (including)
CosignCosign1.6 (including)1.6 (including)
CosignCosign1.7 (including)1.7 (including)
CosignCosign1.8 (including)1.8 (including)
CosignCosign1.8.5 (including)1.8.5 (including)
CosignCosign1.9 (including)1.9 (including)
CosignCosign2.0.1 (including)2.0.1 (including)
CosignCosign2.0.2 (including)2.0.2 (including)

References