It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade spacewalk-remote-utilsUpgrade python2-mgr-cfgUpgrade python2-mgr-cfg-clientUpgrade mgr-cfg-clientUpgrade python2-mgr-cfg-actionsUpgrade python2-mgr-osa-commonUpgrade mgr-cfg-managementUpgrade mgr-daemonUpgrade python2-mgr-osadUpgrade python2-mgr-virtualization-commonUpgrade mgr-osadUpgrade spacecmdUpgrade python2-mgr-virtualization-hostUpgrade spacewalk-backend-libsUpgrade python2-mgr-cfg-managementUpgrade mgr-virtualization-hostUpgrade mgr-cfg-actionsUpgrade python2-rhnlibUpgrade mgr-cfg | Sep 6, 2019 | Jul 2, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub