It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade python2-rhnlibUpgrade mgr-cfgUpgrade spacewalk-backend-libsUpgrade python2-mgr-virtualization-hostUpgrade spacecmdUpgrade python2-mgr-cfg-managementUpgrade mgr-osadUpgrade mgr-virtualization-hostUpgrade mgr-cfg-actionsUpgrade python2-mgr-osadUpgrade mgr-daemonUpgrade python2-mgr-virtualization-commonUpgrade python2-mgr-cfgUpgrade python2-mgr-cfg-clientUpgrade mgr-cfg-clientUpgrade spacewalk-remote-utilsUpgrade mgr-cfg-managementUpgrade python2-mgr-cfg-actionsUpgrade python2-mgr-osa-common | Sep 6, 2019 | Jul 2, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub