V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2013-7347
CVE
Low

Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by read…

CVSS
3.7
Low
EPSS
0.00
p25
Published
2013-01-01
Updated
2013-01-01
Description

Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by reading the __ac session cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2012-3359 for the base64-encoded storage of the user and password in a cookie.

Tags · CWE
LPE
CWE-264
Affected products
CongaEnterprise_linux
CVSS vector
AV:L/AC:H/Au:N/C:P/I:P/A:P
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: H
High (H)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.003 · p25
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
conga*Tracked
enterprise_linux*Tracked
Source databases
CVE