First published: Thu Mar 15 2007(Updated: )
The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. NOTE: there are limited circumstances under which such an attack is feasible.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Linux | ||
Conga Conga |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.