Red Hat Security Advisory 2012-1186-01

newsbot

newsbot

RSS Feed
Red Hat Security Advisory 2012-1186-01 - Katello allows you to manage the application life-cycle for Linux systems. Katello is used by CloudForms System Engine, an Infrastructure as a Service application that provides tools to update and monitor systems within private and hybrid clouds, and can be used to configure new systems, subscribe to updates, and maintain installations in distributed environments. It was found that the katello-common package's installation script did not correctly generate the secret token used for session cookie generation, leading to every default installation using the same secret token. A remote attacker could use this flaw to create a cookie that would allow them to log into the CloudForms System Engine web interface as any user, without knowing the passwords.

Weiterlesen...
 

Ähnliche Themen

Nginx als Reverse Proxy für Nextcloud und Emby

Senior System & Network Admin in Berlin

Red Hat Security Advisory 2012-1187-01

Red Hat Security Advisory 2012-1543-01

Red Hat Security Advisory 2012-1557-01

Zurück
Oben