|
|
| |
|
| |
perl-RT-Authen-ExternalAuth: privilege escalation
| Package(s): | perl-RT-Authen-ExternalAuth |
CVE #(s): | CVE-2012-2770
|
| Created: | August 10, 2012 |
Updated: | August 15, 2012 |
| Description: |
From the Red Hat advisory:
RT::Authen::ExternalAuth 0.10 and below (for all versions of RT) are vulnerable to an escalation of privilege attack where the URL of a RSS feed of the user can be used to acquire a fully logged-in session as that user. |
| Alerts: |
|
( Log in to post comments)
|
|
|