CVE-2012-2683
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1)…
Does this matter?
Lower severity and a low EPSS score (2.08%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- trevor mckay/cumin · redhat/enterprise mrg
- Source
- secalert@redhat.com
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=830243
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092543.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092562.html
- http://rhn.redhat.com/errata/RHSA-2012-1278.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1281.htmlVendor Advisory
- http://secunia.com/advisories/50660
- http://www.securityfocus.com/bid/55618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78772
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=830243
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092543.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092562.html
- http://rhn.redhat.com/errata/RHSA-2012-1278.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1281.htmlVendor Advisory
- http://secunia.com/advisories/50660
- http://www.securityfocus.com/bid/55618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78772
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.