Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T13:40:24.989Z
Reserved: 2014-12-12T00:00:00
Link: CVE-2014-9386

No data.

Status : Modified
Published: 2014-12-15T18:59:28.630
Modified: 2024-11-21T02:20:45.100
Link: CVE-2014-9386

No data.