Show plain JSON{"id": "CVE-2012-2735", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.9, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 4.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2012-09-28T17:55:01.070", "references": [{"url": "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=832151", "source": "secalert@redhat.com"}, {"url": "http://rhn.redhat.com/errata/RHSA-2012-1278.html", "tags": ["Vendor Advisory"], "source": "secalert@redhat.com"}, {"url": "http://rhn.redhat.com/errata/RHSA-2012-1281.html", "tags": ["Vendor Advisory"], "source": "secalert@redhat.com"}, {"url": "http://secunia.com/advisories/50660", "source": "secalert@redhat.com"}, {"url": "http://www.securityfocus.com/bid/55618", "source": "secalert@redhat.com"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78776", "source": "secalert@redhat.com"}, {"url": "http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=832151", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://rhn.redhat.com/errata/RHSA-2012-1278.html", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://rhn.redhat.com/errata/RHSA-2012-1281.html", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://secunia.com/advisories/50660", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.securityfocus.com/bid/55618", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78776", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-Other"}]}], "descriptions": [{"lang": "en", "value": "Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie."}, {"lang": "es", "value": "Vulnerabilidad de fijaci\u00f3n de sesi\u00f3n en Cumin antes de v0.1.5444, tal y como se usa en Red Hat Enterprise Messaging, Realtime, y Grid (MRG) v2.0 permite a atacantes remotos secuestrar sesiones web a trav\u00e9s de una cookie de sesi\u00f3n modificada a mano."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:trevor_mckay:cumin:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EB8CE3E6-C78F-4363-B731-A7981046EE5B", "versionEndIncluding": "0.1.5192-4"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.3160-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B33C6617-24FB-4C96-A786-D26B074B0569"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4369-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6CF3F68-713E-48E8-8D37-4AE443AF87FC"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4410-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8BDF4FB8-5ECF-4A2F-8066-8C362574B55F"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4494-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6ADC326A-3CE8-4710-870B-BF540CCB4A5E"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4794-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFB4776E-178C-4488-9C98-98859576E343"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.4916-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77B6E427-B880-48EB-8139-2F54381539BB"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5033-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9EABF881-94BA-4E76-8EDB-29A4DB7F68B1"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5037-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "476B4482-38CB-46FB-B05D-CBBCDA87B739"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5054-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F49E39C4-D9D4-44D0-9F24-2DB3EB1E4457"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5068-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75A69413-E0B0-4528-8C42-898866BD3B9B"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5092-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00B69A8C-A652-4CBB-80B1-171630C7420E"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5098-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "11E7AFB1-7864-47D4-AD75-9B9950BE7BBB"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5105-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B9C553FD-1ED7-436A-B4A7-309C79CB7793"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4CBBA885-F992-464D-9DF4-047F824FC02B"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D313A509-35AE-4EA3-9EDC-20CA98293D99"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B84531E0-D82D-43AE-A708-B12C34984B70"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9106FF80-627C-40E1-80E1-E574EB9A6B8C"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5137-5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F46220E7-B924-49D4-B866-3EA6B52F4D45"}, {"criteria": "cpe:2.3:a:trevor_mckay:cumin:0.1.5192-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CACA1231-8272-40A9-B7B3-0141E0F1D7A7"}, {"criteria": "cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C60FA8B1-1802-4522-A088-22171DCF7A93"}], "operator": "OR"}]}], "evaluatorImpact": "Per: http://rhn.redhat.com/errata/RHSA-2012-1278.html\r\n\r\n\" An authenticated user able to\r\npre-set the Cumin session cookie in a victim's browser could possibly use\r\nthis flaw to steal the victim's session after they log into Cumin.\"", "evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/384.html 'CWE-384: Session Fixation'", "sourceIdentifier": "secalert@redhat.com"}