Multiple information leak flaws were found in the way conga, a remote management system, processed Luci site extensions related URL requests, involving the following components: * homebase * cluster * storage * portal_skins/custom * logs A remote attacker could issue a specially-crafted HTTP request against conga that, when processed would lead to unauthorized information disclosure (in various Luci site extension components). This issue was discovered by Jan Pokorny of Red Hat.
This issue affects the version of the conga package, as shipped with Red Hat Enterprise Linux 5. -- This issue did NOT affect the version of the luci package, as shipped with Red Hat Enterprise Linux 6.
Acknowledgements: This issue was discovered by Jan Pokorny of Red Hat.
IssueDescription: Multiple information leak flaws were found in the way conga processed luci site extension-related URL requests. A remote, unauthenticated attacker could issue a specially crafted HTTP request that, when processed, would result in unauthorized information disclosure.
This issue has been addressed in the following products: Red Hat Enterprise Linux 5 Via RHSA-2014:1194 https://rhn.redhat.com/errata/RHSA-2014-1194.html