Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Foreman | Theforeman | * | 1.4.1 (including) |
Foreman | Theforeman | 1.0 (including) | 1.0 (including) |
Foreman | Theforeman | 1.1 (including) | 1.1 (including) |
Foreman | Theforeman | 1.2.0 (including) | 1.2.0 (including) |
Foreman | Theforeman | 1.2.0-rc1 (including) | 1.2.0-rc1 (including) |
Foreman | Theforeman | 1.2.0-rc2 (including) | 1.2.0-rc2 (including) |
Foreman | Theforeman | 1.2.1 (including) | 1.2.1 (including) |
Foreman | Theforeman | 1.2.2 (including) | 1.2.2 (including) |
Foreman | Theforeman | 1.2.3 (including) | 1.2.3 (including) |
Foreman | Theforeman | 1.4.0 (including) | 1.4.0 (including) |
Red Hat Satellite 6.0 | RedHat | foreman-0:1.6.0.44-1.el6sat | * |