CVE-2012-3359: Low severity redhat Conga vulnerability
It was reported that Luci's (Luci is a web based front-end component of the Conga cluster management system) user session timeout feature depended only on JavaScript script running in the user's browser. If user closed browser tab without logging out of Luci session and without closing browser, they could re-open Luci web interface and continue using the session even after the timeout period has elapsed.
References: http://sourceware.org/cluster/conga/
Acknowledgement:
Red Hat would like to thank George Hedfors of Cybercom Sweden East AB for reporting this issue.
Other sources
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3359?
CVE-2012-3359 is rated as a moderate severity vulnerability.
How do I fix CVE-2012-3359?
To fix CVE-2012-3359, update your Red Hat Conga installation to the latest version provided by Red Hat.
What systems are affected by CVE-2012-3359?
CVE-2012-3359 affects Red Hat Conga and Red Hat Enterprise Linux 5 systems.
What type of vulnerability is CVE-2012-3359?
CVE-2012-3359 is a session management vulnerability related to user session timeouts.
What potential risks are associated with CVE-2012-3359?
CVE-2012-3359 could allow unauthorized access to user sessions if the user closes the browser tab without logging out.