Unrated severityNVD Advisory· Published Jul 2, 2019· Updated Aug 4, 2024
CVE-2019-10136
CVE-2019-10136
Description
It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move some digits around, artificially extending the session validity without modifying the checksum.
Affected products
52- osv-coords51 versionspkg:rpm/suse/golang-github-prometheus-alertmanager&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/kiwi-desc-saltboot&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/mgr-cfg&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/mgr-cfg&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/mgr-cfg&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/mgr-cfg&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/mgr-daemon&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/mgr-daemon&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/mgr-daemon&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/mgr-daemon&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/mgr-osad&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/mgr-osad&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/mgr-osad&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/mgr-osad&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/mgr-virtualization&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/mgr-virtualization&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/mgr-virtualization&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/mgr-virtualization&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/release-notes-susemanager&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/release-notes-susemanager-proxy&distro=SUSE%20Manager%20Proxy%203.2pkg:rpm/suse/rhnlib&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/rhnlib&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/rhnlib&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/rhnlib&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/spacecmd&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/spacecmd&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/spacewalk-backend&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Proxy%203.2pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Proxy%20Module%204.0pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/spacewalk-proxy&distro=SUSE%20Manager%20Proxy%203.2pkg:rpm/suse/spacewalk-proxy&distro=SUSE%20Manager%20Proxy%20Module%204.0pkg:rpm/suse/spacewalk-remote-utils&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-CLIENT-TOOLSpkg:rpm/suse/spacewalk-remote-utils&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-CLIENT-TOOLSpkg:rpm/suse/spacewalk-remote-utils&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/spacewalk-remote-utils&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Proxy%203.2pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Proxy%20Module%204.0pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Server%203.2pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/susemanager-doc-indexes&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/susemanager-docs_en&distro=SUSE%20Manager%20Server%20Module%204.0pkg:rpm/suse/susemanager-sync-data&distro=SUSE%20Manager%20Server%20Module%204.0
< 0.16.2-3.3.1+ 50 more
- (no CPE)range: < 0.16.2-3.3.1
- (no CPE)range: < 2.11.1-1.6.2
- (no CPE)range: < 2.11.1-3.6.2
- (no CPE)range: < 0.1.1564399963.cf19a13-1.12.1
- (no CPE)range: < 4.0.9-5.6.3
- (no CPE)range: < 4.0.9-5.6.3
- (no CPE)range: < 4.0.9-1.6.4
- (no CPE)range: < 4.0.9-1.6.5
- (no CPE)range: < 4.0.7-5.8.2
- (no CPE)range: < 4.0.7-5.8.2
- (no CPE)range: < 4.0.7-1.8.2
- (no CPE)range: < 4.0.7-1.8.1
- (no CPE)range: < 4.0.9-5.6.2
- (no CPE)range: < 4.0.9-5.6.2
- (no CPE)range: < 4.0.9-1.6.2
- (no CPE)range: < 4.0.9-1.6.2
- (no CPE)range: < 4.0.8-5.8.3
- (no CPE)range: < 4.0.8-5.8.3
- (no CPE)range: < 4.0.8-1.8.3
- (no CPE)range: < 4.0.8-1.8.4
- (no CPE)range: < 3.2.9-6.35.1
- (no CPE)range: < 3.2.9-0.16.27.1
- (no CPE)range: < 4.0.11-12.16.1
- (no CPE)range: < 4.0.11-12.16.1
- (no CPE)range: < 4.0.11-21.16.1
- (no CPE)range: < 4.0.11-3.10.1
- (no CPE)range: < 4.0.14-18.51.1
- (no CPE)range: < 4.0.14-18.51.1
- (no CPE)range: < 4.0.14-38.49.1
- (no CPE)range: < 4.0.14-3.26.1
- (no CPE)range: < 4.0.25-28.42.1
- (no CPE)range: < 4.0.25-28.42.1
- (no CPE)range: < 4.0.25-55.41.1
- (no CPE)range: < 4.0.25-3.23.1
- (no CPE)range: < 2.8.57.17-3.33.1
- (no CPE)range: < 4.0.22-3.3.1
- (no CPE)range: < 2.8.57.17-3.33.1
- (no CPE)range: < 4.0.22-3.3.1
- (no CPE)range: < 2.8.5.6-3.11.1
- (no CPE)range: < 4.0.12-3.3.1
- (no CPE)range: < 4.0.5-6.12.2
- (no CPE)range: < 4.0.5-6.12.2
- (no CPE)range: < 4.0.5-24.12.2
- (no CPE)range: < 4.0.5-3.9.2
- (no CPE)range: < 2.8.7.17-3.30.1
- (no CPE)range: < 4.0.14-3.3.1
- (no CPE)range: < 2.8.7.17-3.30.1
- (no CPE)range: < 4.0.14-3.3.1
- (no CPE)range: < 4.0-10.3.1
- (no CPE)range: < 4.0-10.3.1
- (no CPE)range: < 4.0.12-3.3.1
- spacewalkproject/spacewalkv5Range: spacewalk all through 2.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/109029mitrevdb-entryx_refsource_BID
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.