CVE Vulnerabilities

CVE-2012-3359

Published: Mar 31, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu

Luci in Red Hat Conga stores the users username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

Affected Software

Name Vendor Start Version End Version
Conga Redhat * *
Enterprise_linux Redhat 5 (including) 5 (including)
Red Hat Enterprise Linux 5 RedHat conga-0:0.12.2-64.el5 *

References