Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2023-11-20T23:20:38.606Z

Updated: 2023-11-20T23:20:38.606Z

Reserved: 2023-11-14T23:57:14.918Z


Link: CVE-2023-6144

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-21T00:15:07.353

Modified: 2023-11-29T17:21:04.480


Link: CVE-2023-6144

JSON object: View

cve-icon Redhat Information

No data.

CWE