Description
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web sessions by setting the session identifier via a manipulation that leverages a second web server within the same domain.
Affected products
- bestpractical / rt3.0.1 – 3.0.1
- bestpractical / rt3.0.2 – 3.0.2
- bestpractical / rt3.0.3 – 3.0.3
- bestpractical / rt3.0.4 – 3.0.4
- bestpractical / rt3.0.5 – 3.0.5
- bestpractical / rt3.0.6 – 3.0.6
- bestpractical / rt3.0.7 – 3.0.7
- bestpractical / rt3.0.7.1 – 3.0.7.1
- bestpractical / rt3.0.8 – 3.0.8
- bestpractical / rt3.0.9 – 3.0.9
- bestpractical / rt3.0.10 – 3.0.10
- bestpractical / rt3.0.11 – 3.0.11
- bestpractical / rt3.0.12 – 3.0.12
- bestpractical / rt3.2.0 – 3.2.0
- bestpractical / rt3.2.1 – 3.2.1
- bestpractical / rt3.2.2 – 3.2.2
- bestpractical / rt3.2.3 – 3.2.3
- bestpractical / rt3.4.0 – 3.4.0
- bestpractical / rt3.4.1 – 3.4.1
- bestpractical / rt3.4.2 – 3.4.2
- bestpractical / rt3.4.3 – 3.4.3
- bestpractical / rt3.4.4 – 3.4.4
- bestpractical / rt3.4.5 – 3.4.5
- bestpractical / rt3.4.6 – 3.4.6
- bestpractical / rt3.6.0 – 3.6.0
- bestpractical / rt3.6.1 – 3.6.1
- bestpractical / rt3.6.2 – 3.6.2
- bestpractical / rt3.6.3 – 3.6.3
- bestpractical / rt3.6.4 – 3.6.4
- bestpractical / rt3.6.5 – 3.6.5
- bestpractical / rt3.6.6 – 3.6.6
- bestpractical / rt3.6.7 – 3.6.7
- bestpractical / rt3.6.8 – 3.6.8
- bestpractical / rt3.6.9 – 3.6.9
- bestpractical / rt3.8.0 – 3.8.0
- bestpractical / rt3.8.1 – 3.8.1
- bestpractical / rt3.8.2 – 3.8.2
- bestpractical / rt3.8.3 – 3.8.3
- bestpractical / rt3.8.4 – 3.8.4
- bestpractical / rt3.8.5 – 3.8.5
References
- MAILING_LISThttp://lists.bestpractical.com/pipermail/rt-announce/2009-November/000177.html
- MISChttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00761.html
- MISChttp://bestpractical.typepad.com/files/rt-3.6.2-3.6.3-session_fixation.v3.patch
- VENDOR_ADVISORYhttp://secunia.com/advisories/37546
- MISChttp://bestpractical.typepad.com/files/rt-3.6.4-3.6.9-session_fixation.v2.patch
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/54472
- MAILING_LISThttp://lists.bestpractical.com/pipermail/rt-announce/2009-November/000176.html
- MISChttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00794.html
- MISChttp://bestpractical.typepad.com/files/rt-3.0.0-session_fixation.v3.patch
- MISChttp://bestpractical.typepad.com/files/rt-3.0.1-3.0.6-session_fixation.v3.patch
- VENDOR_ADVISORYhttp://secunia.com/advisories/37728
- MISChttp://bestpractical.typepad.com/files/rt-3.0.7-3.6.1-session_fixation.v3.patch
- MISChttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00832.html
- MISChttp://blog.bestpractical.com/2009/11/session-fixation-vulnerability.html
- MISChttp://bestpractical.typepad.com/files/rt-3.8-session_fixation.patch
- MISChttp://www.securityfocus.com/bid/37162