HMAC-SHA1 Vulnerability in Plone CMS by Plone
CVE-2008-1396

Currently unrated

Key Information:

Vendor

Plone

Status
Vendor
CVE Published:
20 March 2008

What is CVE-2008-1396?

Plone CMS 3.x is susceptible to a vulnerability that compromises the security of authentication cookies. By using invariant data, including a client username and a server secret, the system makes itself vulnerable to remote attackers. These attackers can exploit this flaw to intercept network traffic, allowing them to gain unauthorized and permanent access to user accounts. Securing the communication channels and strengthening the HMAC implementation are essential to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.