Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2023-11-20T23:20:38.606Z

Updated: 2024-08-02T08:21:17.568Z

Reserved: 2023-11-14T23:57:14.918Z

Link: CVE-2023-6144

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-11-21T00:15:07.353

Modified: 2023-11-29T17:21:04.480

Link: CVE-2023-6144

cve-icon Redhat

No data.