CVE-2012-2681XML External Entity (XXE) Injection in Mckay Cumin

Severity
5.8MEDIUMNVD
GHSA5.0
EPSS
0.7%
top 29.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateMay 14

Description

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages2 packages

NVDtrevor_mckay/cumin0.1.5192-4+8

🔴Vulnerability Details

3
GHSA
Several Zend Products Vulnerable to XXE and XEE attacks2022-05-14
GHSA
GHSA-w3x9-vw38-f9cq: Cumin before 02022-05-13
CVEList
CVE-2012-2681: Cumin before 02012-09-28

📋Vendor Advisories

1
Red Hat
cumin: weak session keys2012-09-19

💬Community

2
Bugzilla
CVE-2012-2680 CVE-2012-2681 CVE-2012-2683 CVE-2012-2684 CVE-2012-2685 CVE-2012-2734 CVE-2012-2735 CVE-2012-3459 cumin various flaws [fedora-all]2012-09-19
Bugzilla
CVE-2012-2681 cumin: weak session keys2012-06-01
CVE-2012-2681 — XML External Entity (XXE) Injection | cvebase