PT-2012-4224 · Red Hat · Red Hat Enterprise Messaging+1
CVSS v2.0
4.9
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cumin versions prior to 0.1.5444
Red Hat Enterprise Messaging, Realtime, and Grid (MRG) version 2.0
Description
A session fixation issue allows remote attackers to hijack web sessions via a crafted session cookie.
Recommendations
For Cumin versions prior to 0.1.5444, update to version 0.1.5444 or later.
For Red Hat Enterprise Messaging, Realtime, and Grid (MRG) version 2.0, consider disabling session cookies or implementing additional security measures to prevent session fixation attacks until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cumin
Red Hat Enterprise Messaging