CVE-2012-3459Mckay Cumin vulnerability

CWE-2646 documents5 sources
Severity
4.9MEDIUMNVD
EPSS
0.4%
top 37.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 28
Latest updateMay 13

Description

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request, which triggers a job attribute change request to Condor.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 6.8 | Impact: 4.9

Affected Packages2 packages

NVDtrevor_mckay/cumin0.1.5192-4+19

🔴Vulnerability Details

2
GHSA
GHSA-v57j-74hq-r78j: Cumin before 02022-05-13
CVEList
CVE-2012-3459: Cumin before 02012-09-28

📋Vendor Advisories

1
Red Hat
cumin: allows for editing internal Condor job attributes2012-09-19

💬Community

2
Bugzilla
CVE-2012-2680 CVE-2012-2681 CVE-2012-2683 CVE-2012-2684 CVE-2012-2685 CVE-2012-2734 CVE-2012-2735 CVE-2012-3459 cumin various flaws [fedora-all]2012-09-19
Bugzilla
CVE-2012-3459 cumin: allows for editing internal Condor job attributes2012-08-08
CVE-2012-3459 — Trevor Mckay Cumin vulnerability | cvebase