CVE-2012-3359 describes a vulnerability in Luci within Red Hat Conga and Red Hat Enterprise Linux where user credentials (username and password) are stored as a Base64 encoded string in the __ac session cookie. This allows an attacker with local access to the system to potentially gain privileges by accessing this cookie. The vulnerability has a CVSS score of 3.7, indicating low severity, with an attack vector requiring local access and high attack complexity, leading to partial confidentiality, integrity, and availability impacts. There is no known exploit intelligence, such as Metasploit modules or ExploitDB entries, and the vulnerability has received no community discussion or media coverage, suggesting a low likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:redhat:conga:*:*:*:*:*:*:*:* | ||
5CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.