A remotely exploitable vulnerability has been discovered that allows attackers to bypass cosign weblogin server authentication and assume the identity of an arbitrary user on a cosign-protected service. Organizations that run their own central cosign weblogin server should upgrade their weblogin server to cosign 2.0.2a, cosign 1.9.4b, or back-port the patch available at http://weblogin.org/download.html to the version of cosign they are running.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55877/cosign-vuln-2007-001.txt
Source: https://packetstormsecurity.com/files/55877/cosign-vuln-2007-001.txt.html

