Red Hat Bugzilla – Bug 438379
CVE-2008-1394 Plone stores a password in a cookie
Last modified: 2008-03-20 13:27:32 EDT
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1394 to the following vulnerability:
Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.
Fedora Project does not consider this a security issue.
For secure communication over HTTP, SSL/TLS should be used.