Vulnerabilities > CVE-2012-3359 - Credentials Management vulnerability in Redhat Conga and Enterprise Linux

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.

Vulnerable Configurations

Part Description Count
Application
Redhat
1
OS
Redhat
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyRed Hat Local Security Checks
    NASL idREDHAT-RHSA-2013-0128.NASL
    descriptionUpdated conga packages that fix one security issue, multiple bugs, and add two enhancements are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Conga project is a management system for remote workstations. It consists of luci, which is a secure web-based front end, and ricci, which is a secure daemon that dispatches incoming messages to underlying management modules. It was discovered that luci stored usernames and passwords in session cookies. This issue prevented the session inactivity timeout feature from working correctly, and allowed attackers able to get access to a session cookie to obtain the victim
    last seen2020-06-01
    modified2020-06-02
    plugin id64074
    published2013-01-24
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/64074
    titleRHEL 5 : conga (RHSA-2013:0128)
  • NASL familyCentOS Local Security Checks
    NASL idCENTOS_RHSA-2013-0128.NASL
    descriptionUpdated conga packages that fix one security issue, multiple bugs, and add two enhancements are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Conga project is a management system for remote workstations. It consists of luci, which is a secure web-based front end, and ricci, which is a secure daemon that dispatches incoming messages to underlying management modules. It was discovered that luci stored usernames and passwords in session cookies. This issue prevented the session inactivity timeout feature from working correctly, and allowed attackers able to get access to a session cookie to obtain the victim
    last seen2020-06-01
    modified2020-06-02
    plugin id63573
    published2013-01-17
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/63573
    titleCentOS 5 : conga (CESA-2013:0128)
  • NASL familyOracle Linux Local Security Checks
    NASL idORACLELINUX_ELSA-2013-0128.NASL
    descriptionFrom Red Hat Security Advisory 2013:0128 : Updated conga packages that fix one security issue, multiple bugs, and add two enhancements are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. The Conga project is a management system for remote workstations. It consists of luci, which is a secure web-based front end, and ricci, which is a secure daemon that dispatches incoming messages to underlying management modules. It was discovered that luci stored usernames and passwords in session cookies. This issue prevented the session inactivity timeout feature from working correctly, and allowed attackers able to get access to a session cookie to obtain the victim
    last seen2020-06-01
    modified2020-06-02
    plugin id68699
    published2013-07-12
    reporterThis script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/68699
    titleOracle Linux 5 : conga (ELSA-2013-0128)
  • NASL familyScientific Linux Local Security Checks
    NASL idSL_20130108_CONGA_ON_SL5_X.NASL
    descriptionIt was discovered that luci stored usernames and passwords in session cookies. This issue prevented the session inactivity timeout feature from working correctly, and allowed attackers able to get access to a session cookie to obtain the victim
    last seen2020-03-18
    modified2013-01-17
    plugin id63592
    published2013-01-17
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/63592
    titleScientific Linux Security Update : conga on SL5.x i386/x86_64 (20130108)

Redhat

advisories
bugzilla
id839732
titled a Service Screen is Missing Option for Restart-Disable Recovery Policy
oval
OR
  • commentRed Hat Enterprise Linux must be installed
    ovaloval:com.redhat.rhba:tst:20070304026
  • AND
    • commentRed Hat Enterprise Linux 5 is installed
      ovaloval:com.redhat.rhba:tst:20070331005
    • OR
      • AND
        • commentluci is earlier than 0:0.12.2-64.el5
          ovaloval:com.redhat.rhsa:tst:20130128001
        • commentluci is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhba:tst:20070331002
      • AND
        • commentricci is earlier than 0:0.12.2-64.el5
          ovaloval:com.redhat.rhsa:tst:20130128003
        • commentricci is signed with Red Hat redhatrelease key
          ovaloval:com.redhat.rhba:tst:20070331004
rhsa
idRHSA-2013:0128
released2013-01-08
severityLow
titleRHSA-2013:0128: conga security, bug fix, and enhancement update (Low)
rpms
  • conga-debuginfo-0:0.12.2-64.el5
  • luci-0:0.12.2-64.el5
  • ricci-0:0.12.2-64.el5