Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Red Hat Enterprise MRG 6: RHSA-2012:0477-01 Moderate: XSS Fix

red hat
Calendar Grey April 12, 2012
Dist Redhat Esm H88
Red Hat enhances the MRG Management Interface by addressing several significant security vulnerabilities impacting corporate servers.
An updated MRG Management Console package that fixes several security issues is now available for Red Hat Enterprise MRG 2 for Red Hat Enterprise Linux 6

Solution

Before applying this update, make sure all previously-released errata relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258

Summary

Red Hat Enterprise MRG (Messaging, Realtime, and Grid) is a next-generation IT infrastructure for enterprise computing. MRG offers increased performance, reliability, interoperability, and faster computing for enterprise customers.
Several cross-site scripting (XSS) flaws were found in the MRG Management Console (Cumin). An authorized user on the local network could use these flaws to perform cross-site scripting attacks against MRG Management Console users. Note: Refer to the MRG Messaging User Guide for information on configuring authentication and authorization in the MRG Messaging broker. (CVE-2012-1575)
Users of Red Hat Enterprise MRG Management Console are advised to upgrade to this updated package, which corrects these issues. The MRG Management Console must be restarted ("service cumin restart") for this update to take effect.

References

https://access.redhat.com/security/cve/CVE-2012-1575 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/search/

Package List

MRG Grid for RHEL 6 Server v.2:
Source:
noarch: cumin-0.1.5192-5.el6.noarch.rpm
MRG Management for RHEL 6 Server v.2:
Source:
noarch: cumin-0.1.5192-5.el6.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package


Advisory ID: RHSA-2012:0477-01
Product: Red Hat Enterprise MRG for RHEL-6
Issue date: 2012-04-12

Topic

An updated MRG Management Console package that fixes several securityissues is now available for Red Hat Enterprise MRG 2 for Red HatEnterprise Linux 6.The Red Hat Security Response Team has rated this update as having moderatesecurity impact. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available from the CVE link inthe References section.

Relevant Releases Architectures

MRG Grid for RHEL 6 Server v.2 - noarch

MRG Management for RHEL 6 Server v.2 - noarch

Bugs Fixed

805712 - CVE-2012-1575 cumin: multiple XSS flaws

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here