Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.
CVSS Details
- CVSS 3.1 Base Score: 4.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade luciUpgrade ricci | Dec 1, 2016 | Mar 31, 2014 |
| Oracle_linux | — | Upgrade luciUpgrade ricci | Oct 16, 2024 | Mar 30, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 7, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub