7.5

CVE-2009-5014

The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication via a forged authorization cookie, a related issue to CVE-2010-3852.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TurbogearsTurbogears2 Version <= 2.1b2
TurbogearsTurbogears2 Version1.9.7a2
TurbogearsTurbogears2 Version1.9.7a3
TurbogearsTurbogears2 Version1.9.7a4
TurbogearsTurbogears2 Version1.9.7b1
TurbogearsTurbogears2 Version1.9.7b2
TurbogearsTurbogears2 Version2.0 Updaterc1
TurbogearsTurbogears2 Version2.0.1
TurbogearsTurbogears2 Version2.0b1
TurbogearsTurbogears2 Version2.0b2
TurbogearsTurbogears2 Version2.0b3
TurbogearsTurbogears2 Version2.0b4
TurbogearsTurbogears2 Version2.0b5
TurbogearsTurbogears2 Version2.0b6
TurbogearsTurbogears2 Version2.0b7
TurbogearsTurbogears2 Version2.1a1
TurbogearsTurbogears2 Version2.1a2
TurbogearsTurbogears2 Version2.1a3
TurbogearsTurbogears2 Version2.1b1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.506
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P