Red Hat Bugzilla – Bug 845124
CVE-2012-3448 ganglia: arbitrary script execution vulnerability
Last modified: 2015-08-22 12:45:06 EDT
Upstream has released Ganglia Web 3.5.1  which includes a fix for a security flaw going back to 3.1.7 and possibly earlier versions. This flaw can lead to the arbitrary execution of scripts with the privileges of the web user (apache or nobody), which could possibly lead to other compromises or data exposure. This flaw has been fixed in upstream 3.5.1. No further information is currently available regarding the flaw or a patch.
Current Fedora and EPEL ship 3.7.1