Description
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2176 | It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T22:10:09.975Z
Reserved: 2019-03-27T00:00:00.000Z
Link: CVE-2019-10136
No data.
Status : Modified
Published: 2019-07-02T20:15:11.370
Modified: 2024-11-21T04:18:29.543
Link: CVE-2019-10136
OpenCVE Enrichment
No data.
Weaknesses
EUVD