Red Hat Security Advisory 2012-1187-01

newsbot

newsbot

RSS Feed
Red Hat Security Advisory 2012-1187-01 - Katello allows you to manage the application life-cycle for Linux systems. Katello is used by Red Hat Subscription Asset Manager, a distributor application for handling subscription information and software updates on client machines. It was found that the katello-common package's installation script did not correctly generate the secret token used for session cookie generation, leading to every default installation using the same secret token. A remote attacker could use this flaw to create a cookie that would allow them to log into the Subscription Asset Manager web interface as any user, without knowing the passwords.

Weiterlesen...
 

Ähnliche Themen

Red Hat Security Advisory 2012-1186-01

Red Hat Security Advisory 2012-1559-01

Red Hat Security Advisory 2012-1557-01

Red Hat Security Advisory 2012-1508-01

Red Hat Security Advisory 2012-1506-01

Zurück
Oben