Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat Conga Luci授权问题漏洞
Vulnerability Description
Red Hat Conga是美国红帽(Red Hat)公司的一套基于Web的集群管理工具。该工具主要有Luci和Ricci两部分组成,Ricci是运行于每一个集群节点上的代理;Luci主要用于搭建集群系统,并通过Ricci和集群中的节点进行通讯。 Red Hat Conga中的Luci 0.22.4以及之前版本的默认配置使用"[INSERT SECRET HERE]"作为cookie的密钥。远程攻击者更容易借助伪造ticket cookie绕过repoze.who认证。
CVSS Information
N/A
Vulnerability Type
N/A