The conga packages provide a web-based administration tool for remotecluster and storage management.A privilege escalation flaw was found in luci, the Conga web-basedadministration application. A remote attacker could possibly use this flawto obtain administrative access, allowing them to read, create, or modifythe content of the luci application. (CVE-2011-0720)Users of Conga are advised to upgrade to these updated packages, whichcontain a backported patch to resolve this issue. After installing theupdated packages, luci must be restarted ("service luci restart") for theupdate to take effect.
It was reported that Luci's (Luci is a web based front-end component of the Conga cluster management system) user session timeout feature depended only on JavaScript script running in the user's browser. If user closed browser tab without logging out of Luci session and without closing browser, they could re-open Luci web interface and continue using the session even after the timeout period has elapsed.
References: http://sourceware.org/cluster/conga/
Acknowledgement:
Red Hat would like to thank George Hedfors of Cybercom Sweden East AB for reporting this issue.