CVE-2018-4300
published 2019-04-03CVE-2018-4300: The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web…
PriorityP432medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.84%
76.8th percentile
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | < 2.2.10 | 2.2.10 |
| apple | cups | — | — |
| apple | cups | >= 0 < 2.2.10-1 | 2.2.10-1 |
| apple | cups | >= 0 < 2.2.10-1 | 2.2.10-1 |
| apple | cups | >= 0 < 2.2.10-1 | 2.2.10-1 |
| apple | cups | >= 0 < 2.2.10-1 | 2.2.10-1 |
| debian | cups | < cups 2.2.10-1 (bookworm) | cups 2.2.10-1 (bookworm) |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_asm | — | — |
| f5 | big-ip_dns | — | — |
| f5 | big-ip_edge_gateway | — | — |
| f5 | big-ip_gtm | — | — |
| f5 | big-ip_link_controller | — | — |
| f5 | big-ip_ltm | — | — |
| f5 | big-ip_pem | — | — |
| f5 | big-ip_webaccelerator | — | — |
| f5 | big-ip_websafe | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cups: Session cookie generated by the CUPS web interface is easy to guess
vendor_redhat·2019-04-03·CVSS 5.9
CVE-2018-4300 [MEDIUM] CWE-330 cups: Session cookie generated by the CUPS web interface is easy to guess
cups: Session cookie generated by the CUPS web interface is easy to guess
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
Statement: This vulnerability was originally assigned CVE-2018-4700, but after the publication of security errata the identifier was changed to CVE-2018-4300. Both identifiers refer to the same vulnerability. Since some sources use CVE-2018-4700 and others use CVE-2018-4300, Red Hat security advisories for this vulnerability have been amended to include both identifiers.
Package: cups (Red Hat Enterprise Linux 5) - Will not fix
Package: cups (Red Hat Enterprise Linux 6) - Will not fix
Package
Red Hat
cups: Predictable session cookie breaks CSRF protection
vendor_redhat·2018-12-07·CVSS 5.9
CVE-2018-4700 [MEDIUM] CWE-384 cups: Predictable session cookie breaks CSRF protection
cups: Predictable session cookie breaks CSRF protection
[REJECTED CVE] A predictable session cookie vulnerability was identified in the CUPS printing server. Insufficient randomness in session cookie generation made it easy to guess, undermining CSRF protection. This flaw allowed unauthorized scripted access to the CUPS web interface when enabled, posing a risk of unauthorized control or configuration of the printing server.
Statement: This vulnerability was originally assigned CVE-2018-4700, but after the publication of security errata the identifier was changed to CVE-2018-4300. Both identifiers refer to the same vulnerability. Since some sources use CVE-2018-4700 and others use CVE-2018-4300, Red Hat security advisories for this vulnerability have been amended to include both identifi
F5
CVE-2018-5507: On F5 BIG-IP versions 13
vendor_f5·2018-04-13·CVSS 7.5
CVE-2018-5507 [HIGH] CVE-2018-5507: On F5 BIG-IP versions 13
CVE-2018-5507: On F5 BIG-IP versions 13
On F5 BIG-IP versions 13.0.0, 12.1.0-12.1.3.1, 11.6.1-11.6.2, or 11.5.1-11.5.5, vCMP guests running on VIPRION 2100, 4200 and 4300 series blades cannot correctly decrypt ciphertext from established SSL sessions with small MTU.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator, BIG-IP WebSafe
Affected Versions: 11.5.1 - 11.5.5; 11.6.1 - 11.6.2; 12.1.0 - 12.1.3; 13.0.0
F5 Advisory Articles: K52521791
F5 References: https://support.f5.com/csp/article/K52521791
Debian
CVE-2018-4300: cups - The session cookie generated by the CUPS web interface was easy to guess on Linu...
vendor_debian·2018·CVSS 5.9
CVE-2018-4300 [MEDIUM] CVE-2018-4300: cups - The session cookie generated by the CUPS web interface was easy to guess on Linu...
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
Scope: local
bookworm: resolved (fixed in 2.2.10-1)
bullseye: resolved (fixed in 2.2.10-1)
forky: resolved (fixed in 2.2.10-1)
sid: resolved (fixed in 2.2.10-1)
trixie: resolved (fixed in 2.2.10-1)
GHSA
GHSA-7w9x-rg6m-2fh9: The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the
ghsa_unreviewed·2022-05-13
CVE-2018-4300 [MEDIUM] CWE-200 GHSA-7w9x-rg6m-2fh9: The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
OSV
CVE-2018-4300: The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the
osv·2019-04-03·CVSS 5.9
CVE-2018-4300 [MEDIUM] CVE-2018-4300: The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-4300 cups: Session cookie generated by the CUPS web interface is easy to guess
bugzilla·2019-04-03·CVSS 5.9
CVE-2018-4300 [MEDIUM] CVE-2018-4300 cups: Session cookie generated by the CUPS web interface is easy to guess
CVE-2018-4300 cups: Session cookie generated by the CUPS web interface is easy to guess
The session cookie generated by the CUPS web interface was easy to guess on Linux, allowing unauthorized scripted access to the web interface when the web interface is enabled. This issue affected versions prior to v2.2.10.
References:
https://github.com/apple/cups/releases/tag/v2.2.10
Discussion:
Hi Pedro,
IMO it is the same vulnerability which is being taken care of in https://bugzilla.redhat.com/show_bug.cgi?id=1649347 .
---
Or at least it is the same patch which fixes it :) .
---
Based on upstream ticket https://github.com/apple/cups/issues/5561 closing as duplicate.
*** This bug has been marked as a duplicate of bug 1649347 ***
---
Statement:
This vulnerability was originally assigned
Bugzilla
CVE-2018-4700 cups: Predictable session cookie breaks CSRF protection
bugzilla·2018-11-13·CVSS 5.9
CVE-2018-4700 [MEDIUM] CVE-2018-4700 cups: Predictable session cookie breaks CSRF protection
CVE-2018-4700 cups: Predictable session cookie breaks CSRF protection
A flaw was found in the CUPS printing server. Insufficient randomness makes session cookies predictable, breaking CSRF protection.
Discussion:
Patch:
https://github.com/apple/cups/commit/b9ff93ce913ff633a3f667317e5a81fa7fe0d5d3
---
Created cups tracking bugs for this issue:
Affects: fedora-all [bug 1657750]
---
Stefan, would you mind creating the bugzilla for RHEL 8 too?
---
*** Bug 1695929 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1050 https://access.redhat.com/errata/RHSA-2020:1050
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://ac
http://www.securityfocus.com/bid/107785https://github.com/apple/cups/releases/tag/v2.2.10https://lists.debian.org/debian-lts-announce/2019/09/msg00028.htmlhttp://www.securityfocus.com/bid/107785https://github.com/apple/cups/releases/tag/v2.2.10https://lists.debian.org/debian-lts-announce/2019/09/msg00028.html
2019-04-03
Published