|
|
| |
|
| |
luci: authentication bypass
| Package(s): | luci |
CVE #(s): | CVE-2010-3852
|
| Created: | November 3, 2010 |
Updated: | November 5, 2010 |
| Description: |
From the Red Hat bugzilla:
A security flaw was found in the way Luci administration application
processed ticket cookies. A remote attacker, with certain knowledge
of running Luci instance environment details could use this flaw to
bypass standard Luci authentication mechanism (access resources which
should be otherwise protected by authentication). |
| Alerts: |
|
( Log in to post comments)
|
|
|