AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2012-3359

LOW · CVSS 3.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-03-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2012-3359
Severity
LOW
CVSS
3.7
EPSS
0.34%

Original NVD Description

Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2013-7347 for the incorrect enforcement of a user timeout.