CVE-2014-3521: Red Hat Conga

Medium severity, CVSS 5.5. EPSS: 1.4% chance of exploitation in the next 30 days.

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.

Affected products

Published 2014-10-06. Last modified 2026-06-17.