CollabNet Subversion Edge Management Missing Password Check

Discussion in 'News Aggregator' started by Packet Storm, 30 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    The management frontend does not require the old password for changing the password to a new one. An authenticated attacker may perform password setting attacks via XSRF without knowing the current password. An attacker that stole a Session ID (cookie) is able to gain persistent access by changing the password. Fixed in version 5.0. Version 4.0.11 is affected.

    Continue reading...
     

Share This Page

Loading...