Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request, which triggers a job attribute change request to Condor.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/55632 | vdb entry |
http://rhn.redhat.com/errata/RHSA-2012-1278.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2012-1281.html | vendor advisory |
http://secunia.com/advisories/50660 | third party advisory |
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=846501 | |
http://secunia.com/advisories/50666 | third party advisory vendor advisory |