CVE Vulnerabilities

CVE-2011-4677

Improper Authentication

Published: Dec 06, 2011 | Modified: Dec 06, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
One_click_orgs Oneclickorgs * 1.2.2 (including)
One_click_orgs Oneclickorgs 1.0.0 (including) 1.0.0 (including)
One_click_orgs Oneclickorgs 1.0.1 (including) 1.0.1 (including)
One_click_orgs Oneclickorgs 1.1.0 (including) 1.1.0 (including)
One_click_orgs Oneclickorgs 1.1.1 (including) 1.1.1 (including)
One_click_orgs Oneclickorgs 1.2.0 (including) 1.2.0 (including)
One_click_orgs Oneclickorgs 1.2.1 (including) 1.2.1 (including)

Potential Mitigations

References