CVE-2009-4133
Last modified
CVE-2009-4133 is a vulnerability of currently unknown severity. Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.. EPSS estimates a 2.08% chance of exploitation in the next 30 days.
Description
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Condor Project | Condor | 6.5.4 |
| Condor Project | Condor | 6.8.0 |
| Condor Project | Condor | 6.8.1 |
| Condor Project | Condor | 6.8.2 |
| Condor Project | Condor | 6.8.3 |
| Condor Project | Condor | 6.8.4 |
| Condor Project | Condor | 6.8.5 |
| Condor Project | Condor | 6.8.6 |
| Condor Project | Condor | 6.8.7 |
| Condor Project | Condor | 6.8.8 |
| Condor Project | Condor | 6.8.9 |
| Condor Project | Condor | 7.0.0 |
| Condor Project | Condor | 7.0.1 |
| Condor Project | Condor | 7.0.2 |
| Condor Project | Condor | 7.0.3 |
| Condor Project | Condor | 7.0.4 |
| Condor Project | Condor | 7.0.5 |
| Condor Project | Condor | 7.0.6 |
| Condor Project | Condor | 7.1.0 |
| Condor Project | Condor | 7.1.1 |
| Condor Project | Condor | 7.1.2 |
| Condor Project | Condor | 7.1.3 |
| Condor Project | Condor | 7.1.4 |
| Condor Project | Condor | 7.2.0 |
| Condor Project | Condor | 7.2.1 |
| Condor Project | Condor | 7.2.2 |
| Condor Project | Condor | 7.2.3 |
| Condor Project | Condor | 7.2.4 |
| Condor Project | Condor | 7.3.0 |
| Condor Project | Condor | 7.3.1 |
| Condor Project | Condor | 7.3.2 |
| Condor Project | Condor | 7.4.0 |
| Redhat | Enterprise Mrg | 1.2 |
References
- http://secunia.com/advisories/37766Vendor Advisory
- http://secunia.com/advisories/37803Vendor Advisory
- http://secunia.com/advisories/37766Vendor Advisory
- http://secunia.com/advisories/37803Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4133?
How severe is CVE-2009-4133?
How do I fix CVE-2009-4133?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-4127Unspecified vulnerability in Wikipedia Toolbar extension bef…
- CVE-2009-4128GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the…
- CVE-2009-4129Race condition in Mozilla Firefox allows remote attackers to…
- CVE-2009-4130Visual truncation vulnerability in the MakeScriptDialogTitle…
- CVE-2009-4131The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementatio…
- CVE-2009-4132Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2009-4134Buffer underflow in the rgbimg module in Python 2.5 allows r…
- CVE-2009-4135The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 t…
- CVE-2009-4136PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x b…
- CVE-2009-4137The loadContentFromCookie function in core/Cookie.php in Piw…
- CVE-2009-4138drivers/firewire/ohci.c in the Linux kernel before 2.6.32-gi…
- CVE-2009-4139A flaw was found in Spacewalk Java site packages. This cross…6.8
Are you affected by CVE-2009-4133?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
