| Vulnerability Name: | CVE-2008-4689 (CCN-46084) | ||||||||
| Assigned: | 2008-10-18 | ||||||||
| Published: | 2008-10-18 | ||||||||
| Updated: | 2017-08-08 | ||||||||
| Summary: | Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-287 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-4689 Source: SECUNIA Type: UNKNOWN 32975 Source: CCN Type: GLSA-200812-07 Mantis: Multiple vulnerabilities Source: GENTOO Type: UNKNOWN GLSA-200812-07 Source: CCN Type: Mantis Web site mantisbt - Change Log, mantisbt - 1.1.4 (released 2008-10-18) Source: CONFIRM Type: UNKNOWN http://www.mantisbt.org/bugs/changelog_page.php Source: CONFIRM Type: UNKNOWN http://www.mantisbt.org/bugs/file_download.php?file_id=1988&type=bug Source: CCN Type: Mantis Bug ID: 0009664 Logout without unsetting session cookie Source: CONFIRM Type: UNKNOWN http://www.mantisbt.org/bugs/view.php?id=9664 Source: CCN Type: oss-security Mailing List, Mon, 20 Oct 2008 09:16:52 +0200 Re: CVE request: mantisbt < 1.1.4: RCE Source: MLIST Type: UNKNOWN [oss-security] 20081020 Re: CVE request: mantisbt < 1.1.4: RCE Source: CCN Type: OSVDB ID: 49478 Mantis Cookie Session Hijacking Source: XF Type: UNKNOWN mantis-session-cookie-hijacking(46084) Source: XF Type: UNKNOWN mantis-session-cookie-hijacking(46084) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||