CVE-2012-2684

cumin < 0.1.5444 - SQL Injection via Agent or Object ID

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to execute arbitrary SQL commands via the (1) agent or (2) object id.

References (7)

Core 7
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092562.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/55618
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1278.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2012-1281.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50660
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092543.html

Scores

EPSS 0.0213
EPSS Percentile 80.0%

Details

CWE
CWE-89
Status published
Products (21)
redhat/enterprise_mrg 2.0
trevor_mckay/cumin 0.1.3160-1
trevor_mckay/cumin 0.1.4369-1
trevor_mckay/cumin 0.1.4410-2
trevor_mckay/cumin 0.1.4494-1
trevor_mckay/cumin 0.1.4794-1
trevor_mckay/cumin 0.1.4916-1
trevor_mckay/cumin 0.1.5033-1
trevor_mckay/cumin 0.1.5037-1
trevor_mckay/cumin 0.1.5054-1
... and 11 more
Published Sep 28, 2012
Tracked Since Feb 18, 2026