|
|
| |
|
| |
conga: leaks authentication credentials
| Package(s): | conga |
CVE #(s): | CVE-2012-3359
|
| Created: | January 14, 2013 |
Updated: | January 17, 2013 |
| Description: |
From the Red Hat advisory:
It was discovered that luci stored usernames and passwords in session
cookies. This issue prevented the session inactivity timeout feature from
working correctly, and allowed attackers able to get access to a session
cookie to obtain the victim's authentication credentials. |
| Alerts: |
|
( Log in to post comments)
|
|
|