CVE Vulnerabilities

CVE-2019-10136

Improper Verification of Cryptographic Signature

Published: Jul 02, 2019 | Modified: Feb 12, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
4.3 LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Ubuntu

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Satellite Redhat 5.8 (including) 5.8 (including)
Spacewalk Redhat * 2.9 (including)
Red Hat Satellite 5.8 RedHat spacewalk-backend-0:2.5.3-177.el6sat *

References