First published: Wed Aug 15 2012(Updated: )
The Authen::ExternalAuth extension before 0.11 for Best Practical Solutions RT allows remote attackers to obtain a logged-in session via unspecified vectors related to the "URL of a RSS feed of the user."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mike Peachey Authen | <=0.08 | |
Mike Peachey Authen | =\-externalauth | |
Best Practical Solutions Request Tracker |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2770 has a moderate severity level as it allows remote attackers to obtain a logged-in session.
To fix CVE-2012-2770, upgrade to Authen::ExternalAuth version 0.11 or later.
CVE-2012-2770 affects Authen::ExternalAuth versions prior to 0.11.
Using older versions of Authen::ExternalAuth is risky due to the vulnerability in CVE-2012-2770.
CVE-2012-2770 allows attackers to obtain access to a logged-in session through unspecified vectors.