CVE-2018-4300: Infoleak
Published Apr 3, 2019
·Updated
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
Affected Software
1 affected component
apple CUPS<2.2.10
Event History
Apr 3, 2019
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2018-4300.
2
What is the severity level of CVE-2018-4300?
The severity level of CVE-2018-4300 is medium.
3
What is the description of CVE-2018-4300?
CVE-2018-4300 is a security vulnerability in the CUPS web interface on Linux that allowed unauthorized scripted access when the web interface is enabled.
4
Which versions of CUPS are affected by CVE-2018-4300?
Versions prior to v2.2.10 of CUPS are affected by CVE-2018-4300.
5
How can I fix the CVE-2018-4300 vulnerability?
To fix the CVE-2018-4300 vulnerability, users should update to version 2.2.10 or later of CUPS.