PT-2012-4732 · Htcondor Team · Cumin

Florian Weimer

·

Published

2012-09-28

·

Updated

2021-07-15

·

CVE-2012-3459

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cumin before version 0.1.5444
Description The issue allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request. This triggers a job attribute change request to Condor.
Recommendations For versions prior to 0.1.5444, consider restricting access to the HTTP POST request endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using crafted additional parameters in HTTP POST requests until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3459
RHSA-2012:1278
RHSA-2012:1281

Affected Products

Cumin