Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.
History

Thu, 09 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Alayacare
Alayacare procura
Weaknesses CWE-287
CPEs cpe:2.3:a:alayacare:procura:*:*:*:*:*:*:*:*
Vendors & Products Alayacare
Alayacare procura

cve-icon MITRE

Status: PUBLISHED

Assigner: TML

Published: 2024-02-16T04:06:17.797Z

Updated: 2024-08-02T08:28:21.849Z

Reserved: 2023-11-30T22:06:55.677Z

Link: CVE-2023-6451

cve-icon Vulnrichment

Updated: 2024-08-02T08:28:21.849Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-16T04:15:08.090

Modified: 2025-01-09T14:56:51.713

Link: CVE-2023-6451

cve-icon Redhat

No data.