CVE-2019-10911 drupal: Part of an expiry time in a remember me cookie could be considered part of the username, where modifying it would lead to authentication as a different user.
Product:
[Other] Security Response
Reporter:
Marian Rehak <mrehak>
Component:
vulnerability
Assignee:
Red Hat Product Security <security-response-team>
Status:
CLOSED
UPSTREAM
QA Contact:
Severity:
medium
Docs Contact:
Priority:
medium
Version:
unspecified
CC:
extras-orphan, fedora, gwync, james.hogarth, shawn, sven
Created php-symfony tracking bugs for this issue:
Affects: epel-all [bug 1711316]
Affects: fedora-all [bug 1711315]
Comment 3Product Security DevOps Team
2019-06-10 10:54:49 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.