CVE Vulnerabilities

CVE-2012-3459

Published: Sep 28, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
4.9 MODERATE
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request, which triggers a job attribute change request to Condor.

Affected Software

NameVendorStart VersionEnd Version
CuminTrevor_mckay*0.1.5192-4 (including)
CuminTrevor_mckay0.1.3160-1 (including)0.1.3160-1 (including)
CuminTrevor_mckay0.1.4369-1 (including)0.1.4369-1 (including)
CuminTrevor_mckay0.1.4410-2 (including)0.1.4410-2 (including)
CuminTrevor_mckay0.1.4494-1 (including)0.1.4494-1 (including)
CuminTrevor_mckay0.1.4794-1 (including)0.1.4794-1 (including)
CuminTrevor_mckay0.1.4916-1 (including)0.1.4916-1 (including)
CuminTrevor_mckay0.1.5033-1 (including)0.1.5033-1 (including)
CuminTrevor_mckay0.1.5037-1 (including)0.1.5037-1 (including)
CuminTrevor_mckay0.1.5054-1 (including)0.1.5054-1 (including)
CuminTrevor_mckay0.1.5068-1 (including)0.1.5068-1 (including)
CuminTrevor_mckay0.1.5092-1 (including)0.1.5092-1 (including)
CuminTrevor_mckay0.1.5098-2 (including)0.1.5098-2 (including)
CuminTrevor_mckay0.1.5105-1 (including)0.1.5105-1 (including)
CuminTrevor_mckay0.1.5137-1 (including)0.1.5137-1 (including)
CuminTrevor_mckay0.1.5137-2 (including)0.1.5137-2 (including)
CuminTrevor_mckay0.1.5137-3 (including)0.1.5137-3 (including)
CuminTrevor_mckay0.1.5137-4 (including)0.1.5137-4 (including)
CuminTrevor_mckay0.1.5137-5 (including)0.1.5137-5 (including)
CuminTrevor_mckay0.1.5192-1 (including)0.1.5192-1 (including)
Enterprise_mrgRedhat2.0 (including)2.0 (including)
MRG for RHEL-5 v. 2RedHatcondor-0:7.6.5-0.22.el5*
MRG for RHEL-5 v. 2RedHatcondor-wallaby-0:4.1.3-1.el5*
MRG for RHEL-5 v. 2RedHatcondor-wallaby-base-db-0:1.23-1.el5*
MRG for RHEL-5 v. 2RedHatcumin-0:0.1.5444-3.el5*
MRG for RHEL-5 v. 2RedHatsesame-0:1.0-4.el5*
MRG for RHEL-5 v. 2RedHatwallaby-0:0.12.5-10.el5*
Red Hat Enterprise MRG 2RedHatcondor-0:7.6.5-0.22.el6*
Red Hat Enterprise MRG 2RedHatcondor-wallaby-0:4.1.3-1.el6*
Red Hat Enterprise MRG 2RedHatcondor-wallaby-base-db-0:1.23-1.el6*
Red Hat Enterprise MRG 2RedHatcumin-0:0.1.5444-3.el6*
Red Hat Enterprise MRG 2RedHatdeltacloud-core-0:0.5.0-10.el6_2*
Red Hat Enterprise MRG 2RedHatlibdeltacloud-0:0.9-1.el6*
Red Hat Enterprise MRG 2RedHatrubygem-daemons-0:1.1.4-2.el6*
Red Hat Enterprise MRG 2RedHatrubygem-eventmachine-0:0.12.10-7.el6*
Red Hat Enterprise MRG 2RedHatrubygem-fssm-0:0.2.7-1.el6*
Red Hat Enterprise MRG 2RedHatrubygem-haml-0:3.1.2-2.el6*
Red Hat Enterprise MRG 2RedHatrubygem-hpricot-0:0.8.4-2.el6*
Red Hat Enterprise MRG 2RedHatrubygem-json-0:1.4.6-10.el6*
Red Hat Enterprise MRG 2RedHatrubygem-maruku-0:0.6.0-4.el6*
Red Hat Enterprise MRG 2RedHatrubygem-mime-types-0:1.16-4.el6_0*
Red Hat Enterprise MRG 2RedHatrubygem-mocha-0:0.9.7-4.el6*
Red Hat Enterprise MRG 2RedHatrubygem-net-ssh-0:2.0.23-6.el6_0*
Red Hat Enterprise MRG 2RedHatrubygem-nokogiri-0:1.5.0-0.8.beta4.el6*
Red Hat Enterprise MRG 2RedHatrubygem-rack-1:1.3.0-2.el6*
Red Hat Enterprise MRG 2RedHatrubygem-rack-accept-0:0.4.3-6.el6_0*
Red Hat Enterprise MRG 2RedHatrubygem-rack-test-0:0.6.1-1.el6*
Red Hat Enterprise MRG 2RedHatrubygem-rake-0:0.8.7-2.1.el6*
Red Hat Enterprise MRG 2RedHatrubygem-rest-client-0:1.6.1-2.el6_0*
Red Hat Enterprise MRG 2RedHatrubygems-0:1.8.16-1.el6*
Red Hat Enterprise MRG 2RedHatrubygem-sass-0:3.1.4-4.el6*
Red Hat Enterprise MRG 2RedHatrubygem-sinatra-1:1.2.6-2.el6*
Red Hat Enterprise MRG 2RedHatrubygem-syntax-0:1.0.0-4.el6*
Red Hat Enterprise MRG 2RedHatrubygem-thin-0:1.2.11-3.el6*
Red Hat Enterprise MRG 2RedHatrubygem-tilt-0:1.3.2-3.el6*
Red Hat Enterprise MRG 2RedHatrubygem-yard-0:0.7.2-1.el6*
Red Hat Enterprise MRG 2RedHatsesame-0:1.0-6.el6*
Red Hat Enterprise MRG 2RedHatwallaby-0:0.12.5-10.el6*

References