Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20663
HistoryJul 08, 2019 - 12:07 a.m.

Insecure Signature Validation

2019-07-0800:07:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.001

Percentile

22.7%

spacewalk uses insecure authentication signature validation. The client token checksums are not properly computed, which would allow an attacker to extend session validity by modifying the authenticated header set without modifying the checksum.

EPSS

0.001

Percentile

22.7%