VDB
CVE-2012-3359
CVE-2012-3359
PUBLISHED
CVSS 3.700000047683716 LOW
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.
EPSS 0.34% · 26.5th percentile
Risk Scores
CVSS 2.0
3.700000047683716
EPSS Score
0.34%
26.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | conga | |
| redhat | enterprise_linux | 5 |
| n/a | n/a | n/a |
Timeline
- Mar 30, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score