Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by leveraging an unattended workstation, aka ZEN-12691.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T13:40:24.989Z
Reserved: 2014-12-12T00:00:00
Link: CVE-2014-9386

No data.

Status : Deferred
Published: 2014-12-15T18:59:28.630
Modified: 2025-04-12T10:46:40.837
Link: CVE-2014-9386

No data.