Florian Weimer reported that authenticated users could instruct Cumin to submit a job attribute change to Condor, simply be submitting a crafted POST request with certain additional parameters. This job could be used to change internal Condor attributes, including the Owner attribute, allowing Cumin users to elevate their privileges.
Acknowledgements: This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
This issue has been addressed in following products: MRG for RHEL-5 v. 2 Via RHSA-2012:1278 https://rhn.redhat.com/errata/RHSA-2012-1278.html
This issue has been addressed in following products: MRG for RHEL-6 v.2 Via RHSA-2012:1281 https://rhn.redhat.com/errata/RHSA-2012-1281.html
Created cumin tracking bugs for this issue Affects: fedora-all [bug 858868]