CVE-2010-3852
Redhat Luci < 0.22.4 - Authentication Bypass
Title source: ruleDescription
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.
References (12)
Scores
EPSS
0.0071
EPSS Percentile
72.0%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
redhat/luci
< 0.22.4
Timeline
Published
Nov 06, 2010
Tracked Since
Feb 18, 2026