CVE-2012-2770: Medium severity Mike Peachey Authen\ vulnerability
Published Aug 15, 2012
·Updated
The Authen::ExternalAuth extension before 0.11 for Best Practical Solutions RT allows remote attackers to obtain a logged-in session via unspecified vectors related to the "URL of a RSS feed of the user."
Affected Software
3 affected components
Mike Peachey Authen\<=0.08
Mike Peachey Authen\=\-externalauth
bestpractical RT
Remediation
Event History
Aug 15, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2770?
CVE-2012-2770 has a moderate severity level as it allows remote attackers to obtain a logged-in session.
2
How do I fix CVE-2012-2770?
To fix CVE-2012-2770, upgrade to Authen::ExternalAuth version 0.11 or later.
3
What software is affected by CVE-2012-2770?
CVE-2012-2770 affects Authen::ExternalAuth versions prior to 0.11.
4
Can I still use older versions of Authen::ExternalAuth after CVE-2012-2770?
Using older versions of Authen::ExternalAuth is risky due to the vulnerability in CVE-2012-2770.
5
What does CVE-2012-2770 allow an attacker to do?
CVE-2012-2770 allows attackers to obtain access to a logged-in session through unspecified vectors.