Description
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
Affected products
- RedHat / luci0.22.4
References
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2010/2900
- MISChttp://www.securityfocus.com/bid/44611
- VENDOR_ADVISORYhttp://secunia.com/advisories/42123
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2010/2873
- MAILING_LISThttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050244.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/42113
- MAILING_LISThttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050309.html
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=626504
- MISChttp://osvdb.org/69015
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/62980
- MISChttp://git.fedorahosted.org/git/?p=luci.git%3Ba=commit%3Bh=9e0bbf0c5faa198379d945474f7d55da5031cacf
- MAILING_LISThttp://lists.fedoraproject.org/pipermail/package-announce/2010-November/050246.html