Bug 731574 (CVE-2011-2925)

Summary: CVE-2011-2925 cumin: broker username/password appears in the log file
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: iboverma, jlieskov, jross, jsarenik, matt, pmackinn, security-response-team, tmckay, tross
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-09 17:19:33 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 728960    
Bug Blocks: 731578    

Description Vincent Danen 2011-08-17 21:11:41 UTC
A flaw was discovered in cumin where it would log broker authentication credentials to the cumin log file.  A local user exploiting this flaw could connect to the broker outside of cumin's control and perform certain operations such as scheduling jobs, setting attributes on jobs, as well as holding, releasing or removing jobs.  The user could also use this to, depending on the defined ACLs of the broker, manipulate message queues and other privileged operations.

Comment 2 Vincent Danen 2011-08-18 20:43:21 UTC
Note that in MRG 2, the broker username and password are stored in configuration files that are not  publicly readable (unlike MRG 1.3).  As well, in MRG 1.3, cumin operations were not restricted by any authentication, unlike MRG 2 where authentication is required.  This makes the exposure of credentials in the MRG 2 log files much more significant than on MRG 1.3.

Comment 4 errata-xmlrpc 2011-09-07 16:40:35 UTC
This issue has been addressed in following products:

  MRG for RHEL-6 v.2

Via RHSA-2011:1250 https://rhn.redhat.com/errata/RHSA-2011-1250.html

Comment 5 errata-xmlrpc 2011-09-07 16:40:51 UTC
This issue has been addressed in following products:

  MRG for RHEL-5 v. 2

Via RHSA-2011:1249 https://rhn.redhat.com/errata/RHSA-2011-1249.html