CVE-2018-4300 PUBLISHED

The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.

EPSS 0.49% · 65.4th percentile

Risk Scores

EPSS Score
0.49%
65.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTScups0, 1.7.0~rc1-0ubuntu5, 1.7.0-0ubuntu2
Ubuntu:16.04:LTScups0, 2.1.0-4ubuntu3, 2.1.0-5
Ubuntu:18.04:LTScups0, 2.2.4-7ubuntu2, 2.2.5-2

Timeline

References

Open in Interactive Console →