Total vulnerabilities in the database
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.
Software | From | Fixed in |
---|---|---|
redhat / satellite | 5.8 | 5.8.x |
redhat / spacewalk | - | 2.9.x |