CVE-2014-0090: Medium severity theforeman foreman vulnerability
Jeremy Choi and Keqin Hong of the Red Hat HSS Pen-Test Team reported that under some circumstances foreman did not generate new session-id's for every login. This flaw could allow authentication to be bypassed through session fixation attacks.
Other sources
Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0090?
CVE-2014-0090 has a medium severity rating due to its potential for session fixation attacks.
How do I fix CVE-2014-0090?
To fix CVE-2014-0090, upgrade Foreman to version 1.4.2 or later.
What types of attacks are possible with CVE-2014-0090?
CVE-2014-0090 could allow attackers to perform session fixation attacks, potentially leading to unauthorized access.
Which versions of Foreman are affected by CVE-2014-0090?
CVE-2014-0090 affects Foreman versions prior to 1.4.2, including 1.0, 1.1, 1.2.0, and 1.4.1.
Who reported the vulnerability CVE-2014-0090?
CVE-2014-0090 was reported by Jeremy Choi and Keqin Hong from the Red Hat HSS Pen-Test Team.