Vulnerability Description
Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
CVSS Score
7.5
HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mantis | Mantis | <= 1.1.2 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/32975
- http://www.gentoo.org/security/en/glsa/glsa-200812-07.xml
- http://www.mantisbt.org/bugs/changelog_page.php
- http://www.mantisbt.org/bugs/file_download.php?file_id=1988&type=bug
- http://www.mantisbt.org/bugs/view.php?id=9664
- http://www.openwall.com/lists/oss-security/2008/10/20/1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46084
- http://secunia.com/advisories/32975
- http://www.gentoo.org/security/en/glsa/glsa-200812-07.xml
- http://www.mantisbt.org/bugs/changelog_page.php
- http://www.mantisbt.org/bugs/file_download.php?file_id=1988&type=bug
- http://www.mantisbt.org/bugs/view.php?id=9664
- http://www.openwall.com/lists/oss-security/2008/10/20/1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46084
FAQ
What is CVE-2008-4689?
CVE-2008-4689 is a vulnerability with a CVSS score of 7.5 (HIGH). Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.
How severe is CVE-2008-4689?
CVE-2008-4689 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-4689?
Check the references section above for vendor advisories and patch information. Affected products include: Mantis Mantis.