Vulnerability Name: | CVE-2007-1462 (CCN-33235) | ||||||||
Assigned: | 2007-02-13 | ||||||||
Published: | 2007-02-13 | ||||||||
Updated: | 2023-02-13 | ||||||||
Summary: | The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. Note: there are limited circumstances under which such an attack is feasible. | ||||||||
CVSS v3 Severity: | 6.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:U/RC:C)
4.2 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N/E:U/RL:U/RC:C)
| ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-1462 Source: CCN Type: OSVDB ID: 35086 Conga luci Server Component Hidden Field Password Disclosure Source: CCN Type: Red Hat Bugzilla Bug 228637 CVE-2007-1462 security alert - passwords sent back from server as input value Source: secalert@redhat.com Type: Vendor Advisory secalert@redhat.com Source: XF Type: UNKNOWN conga-luci-password-plaintext(33235) | ||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |