See how conga compares to other vendors in security performance
The luci server component in conga preserves the password between page loads for the Add System/Cluster task flow by storing the password in the Value attribute of a password entry field, which allows attackers to steal the password by performing a "view source" or other operation to obtain the web page. NOTE: there are limited circumstances under which such an attack is feasible.
The conga packages provide a web-based administration tool for remotecluster and storage management.A privilege escalation flaw was found in luci, the Conga web-basedadministration application. A remote attacker could possibly use this flawto obtain administrative access, allowing them to read, create, or modifythe content of the luci application. (CVE-2011-0720)Users of Conga are advised to upgrade to these updated packages, whichcontain a backported patch to resolve this issue. After installing theupdated packages, luci must be restarted ("service luci restart") for theupdate to take effect.