The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the header the current session of the user. This session could then be stolen by a man-in-the-middle.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-11-22T19:00:00
Updated: 2024-08-05T11:37:11.446Z
Reserved: 2018-11-22T00:00:00
Link: CVE-2018-19443
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-11-22T19:29:00.220
Modified: 2024-11-21T03:57:55.777
Link: CVE-2018-19443
Redhat
No data.