Unrated severityNVD Advisory· Published Nov 6, 2010· Updated Apr 29, 2026
CVE-2010-3852
CVE-2010-3852
Description
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/42113nvdVendor Advisory
- secunia.com/advisories/42123nvdVendor Advisory
- www.vupen.com/english/advisories/2010/2873nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2010-November/050244.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-November/050246.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-November/050309.htmlnvd
- osvdb.org/69015nvd
- www.securityfocus.com/bid/44611nvd
- www.vupen.com/english/advisories/2010/2900nvd
- bugzilla.redhat.com/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/62980nvd
News mentions
0No linked articles in our index yet.