CVE-2012-3459
Summary
| CVE | CVE-2012-3459 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-09-28 17:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request, which triggers a job attribute change request to Condor. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Mrg | 2.0 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.3160-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4369-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4410-2 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4494-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4794-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.4916-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5033-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5037-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5054-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5068-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5092-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5098-2 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5105-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-1 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-2 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-3 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-4 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5137-5 | All | All | All |
| Application | Trevor Mckay | Cumin | 0.1.5192-1 | All | All | All |
| Application | Trevor Mckay | Cumin | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| Security Advisory SA50666 - Condor Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Condor Multiple Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 846501 – (CVE-2012-3459) CVE-2012-3459 cumin: allows for editing internal Condor job attributes | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.