Total vulnerabilities in the database
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
Software | From | Fixed in |
---|---|---|
redhat / luci | - | 0.22.4.x |