Back

HIGH

cups: improper use of the 'guest' username in the web UI, when user not logged on to the server

Published Nov 21, 2008

Description

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of CUPS as shipped with Red Hat Enterprise Linux 3, 4, or 5. Versions shipped do not support RSS subscriptions.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Nov 21, 2008
Updated Aug 7, 2024
Reserved Nov 20, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Mar 27, 2008