LWN.net Logo

conga: leaks authentication credentials

Package(s):conga CVE #(s):CVE-2012-3359
Created:January 14, 2013 Updated:January 17, 2013
Description: From the Red Hat advisory:

It was discovered that luci stored usernames and passwords in session cookies. This issue prevented the session inactivity timeout feature from working correctly, and allowed attackers able to get access to a session cookie to obtain the victim's authentication credentials.

Alerts:
Oracle ELSA-2013-0128 2013-01-12
Scientific Linux SL-cong-20130116 2013-01-16
CentOS CESA-2013:0128 2013-01-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds