Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://condor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1018 - | |
References | () http://secunia.com/advisories/37766 - Vendor Advisory | |
References | () http://secunia.com/advisories/37803 - Vendor Advisory | |
References | () http://securitytracker.com/id?1023378 - | |
References | () http://www.cs.wisc.edu/condor/manual/v7.4/8_3Stable_Release.html#SECTION00931000000000000000 - Vendor Advisory | |
References | () http://www.cs.wisc.edu/condor/security/vulnerabilities/CONDOR-2009-0001.html - Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2009-1688.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2009-1689.html - | |
References | () http://www.securityfocus.com/bid/37443 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=544371 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/54984 - |
Information
Published : 2009-12-23 18:30
Updated : 2024-11-21 01:08
NVD link : CVE-2009-4133
Mitre link : CVE-2009-4133
CVE.ORG link : CVE-2009-4133
JSON object : View
Products Affected
condor_project
- condor
redhat
- enterprise_mrg
CWE