Information Exposure

Affecting cups package, versions <1.7.5-11+deb8u6

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

NVD Description

Note: Versions mentioned in the description apply to the upstream cups package. See Remediation section below for Debian:8 relevant versions.

The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.

Remediation

Upgrade Debian:8 cups to version 1.7.5-11+deb8u6 or higher.

References

CVSS Score

5.9
medium severity
  • Attack Vector
    Network
  • Attack Complexity
    High
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    High
  • Integrity
    None
  • Availability
    None
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE
CVE-2018-4300
CWE
CWE-200
Snyk ID
SNYK-DEBIAN8-CUPS-456728
Disclosed
03 Apr, 2019
Published
05 Aug, 2019