CVE Vulnerabilities

CVE-2009-5014

Published: Nov 06, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authorization cookie, a related issue to CVE-2010-3852.

Affected Software

NameVendorStart VersionEnd Version
Turbogears2Turbogears*2.1b2 (including)
Turbogears2Turbogears1.9.7a2 (including)1.9.7a2 (including)
Turbogears2Turbogears1.9.7a3 (including)1.9.7a3 (including)
Turbogears2Turbogears1.9.7a4 (including)1.9.7a4 (including)
Turbogears2Turbogears1.9.7b1 (including)1.9.7b1 (including)
Turbogears2Turbogears1.9.7b2 (including)1.9.7b2 (including)
Turbogears2Turbogears2.0-rc1 (including)2.0-rc1 (including)
Turbogears2Turbogears2.0.1 (including)2.0.1 (including)
Turbogears2Turbogears2.0b1 (including)2.0b1 (including)
Turbogears2Turbogears2.0b2 (including)2.0b2 (including)
Turbogears2Turbogears2.0b3 (including)2.0b3 (including)
Turbogears2Turbogears2.0b4 (including)2.0b4 (including)
Turbogears2Turbogears2.0b5 (including)2.0b5 (including)
Turbogears2Turbogears2.0b6 (including)2.0b6 (including)
Turbogears2Turbogears2.0b7 (including)2.0b7 (including)
Turbogears2Turbogears2.1a1 (including)2.1a1 (including)
Turbogears2Turbogears2.1a2 (including)2.1a2 (including)
Turbogears2Turbogears2.1a3 (including)2.1a3 (including)
Turbogears2Turbogears2.1b1 (including)2.1b1 (including)
Turbogears2Ubuntuupstream*

References