It was found that multiple forms in the cumin web interface did not protect against Cross-Site Request Forgery (CSRF) attacks. If a remote attacker could trick a user, who is logged into the cumin web interface, into visiting a specially crafted URL, the attacker could perform actions in the context of the logged in user.
Acknowledgements: This issue was discovered by Tomáš Nováčik of the Red Hat MRG Quality Engineering team.
This issue has been addressed in following products: MRG for RHEL-6 v.2 Via RHSA-2013:1852 https://rhn.redhat.com/errata/RHSA-2013-1852.html
This issue has been addressed in following products: MRG for RHEL-5 v. 2 Via RHSA-2013:1851 https://rhn.redhat.com/errata/RHSA-2013-1851.html