PT-2012-4223 · Red Hat · Red Hat Enterprise Messaging+1

Florian Weimer

·

Published

2012-09-28

·

Updated

2023-02-13

·

CVE-2012-2734

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cumin versions prior to 0.1.5444 Red Hat Enterprise Messaging, Realtime, and Grid (MRG) version 2.0
Description The issue allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands.
Recommendations For Cumin versions prior to 0.1.5444, update to version 0.1.5444 or later. For Red Hat Enterprise Messaging, Realtime, and Grid (MRG) version 2.0, consider disabling or restricting access to commands that can be executed via requests until a patch is available.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2012-2734
RHSA-2012:1278
RHSA-2012:1281

Affected Products

Cumin
Red Hat Enterprise Messaging