356
VMScore

CVE-2019-10136

Published: 02/07/2019 Updated: 12/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

It was found that Spacewalk, all versions up to and including 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat satellite 5.8

redhat spacewalk

Vendor Advisories

Synopsis Low: spacewalk-backend security update Type/Severity Security Advisory: Low Topic An update for spacewalk-backend is now available for Red Hat Satellite 58Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, wh ...
Impact: Low Public Date: 2019-07-01 CWE: CWE-347 Bugzilla: 1708696: CVE-2019-10136 spacewalk: Insecure ...