CVE-2009-4133
Last modified
CVE-2009-4133 is a vulnerability of currently unknown severity. Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.. EPSS estimates a 2.08% chance of exploitation in the next 30 days.
Description
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Condor Project | Condor | 6.5.4 |
| Condor Project | Condor | 6.8.0 |
| Condor Project | Condor | 6.8.1 |
| Condor Project | Condor | 6.8.2 |
| Condor Project | Condor | 6.8.3 |
| Condor Project | Condor | 6.8.4 |
| Condor Project | Condor | 6.8.5 |
| Condor Project | Condor | 6.8.6 |
| Condor Project | Condor | 6.8.7 |
| Condor Project | Condor | 6.8.8 |
| Condor Project | Condor | 6.8.9 |
| Condor Project | Condor | 7.0.0 |
| Condor Project | Condor | 7.0.1 |
| Condor Project | Condor | 7.0.2 |
| Condor Project | Condor | 7.0.3 |
| Condor Project | Condor | 7.0.4 |
| Condor Project | Condor | 7.0.5 |
| Condor Project | Condor | 7.0.6 |
| Condor Project | Condor | 7.1.0 |
| Condor Project | Condor | 7.1.1 |
| Condor Project | Condor | 7.1.2 |
| Condor Project | Condor | 7.1.3 |
| Condor Project | Condor | 7.1.4 |
| Condor Project | Condor | 7.2.0 |
| Condor Project | Condor | 7.2.1 |
| Condor Project | Condor | 7.2.2 |
| Condor Project | Condor | 7.2.3 |
| Condor Project | Condor | 7.2.4 |
| Condor Project | Condor | 7.3.0 |
| Condor Project | Condor | 7.3.1 |
| Condor Project | Condor | 7.3.2 |
| Condor Project | Condor | 7.4.0 |
| Redhat | Enterprise Mrg | 1.2 |
References
- http://secunia.com/advisories/37766Vendor Advisory
- http://secunia.com/advisories/37803Vendor Advisory
- http://secunia.com/advisories/37766Vendor Advisory
- http://secunia.com/advisories/37803Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4133?
How severe is CVE-2009-4133?
How do I fix CVE-2009-4133?
Are you affected by CVE-2009-4133?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
