Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jan Pokorny

#44670of 56,331
6.4Total CVSS
Vulnerabilities · 1
PT-2010-5121
6.4
2010-11-05
Red Hat · Luci · CVE-2010-3852
**Name of the Vulnerable Software and Affected Versions** Luci versions 0.22.4 and earlier **Description** The default configuration of Luci in Red Hat Conga uses a static secret key for cookies, which makes it easier for remote attackers to bypass authentication via a forged ticket cookie. **Recommendations** For Luci versions 0.22.4 and earlier, update the secret key for cookies to a unique and secure value to prevent bypassing of repoze.who authentication.