The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade cups | Jul 30, 2024 | Nov 21, 2008 |
| Suse | — | Upgrade cupsUpgrade cups-libsUpgrade cups-clientUpgrade cups-libs-32bitUpgrade cups-libs-64bitUpgrade cups-devel | Feb 17, 2015 | Nov 20, 2008 |
| Ubuntu | — | Upgrade cupsUpgrade cupsys | Nov 8, 2024 | Nov 21, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub