CVE-2009-4133
published 2009-12-23CVE-2009-4133: Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as…
PriorityP434medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.08%
79.4th percentile
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
| condor_project | condor | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Condor: queue super user cannot drop privs
vendor_redhat·2010-01-15·CVSS 6.5
CVE-2009-4133 [MEDIUM] Condor: queue super user cannot drop privs
Condor: queue super user cannot drop privs
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
Debian
CVE-2009-4133: condor - Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and ...
vendor_debian·2009·CVSS 6.5
CVE-2009-4133 [MEDIUM] CVE-2009-4133: condor - Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and ...
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-4crj-cmpw-2wrg: Condor 6
ghsa_unreviewed·2022-05-02
CVE-2009-4133 [MEDIUM] GHSA-4crj-cmpw-2wrg: Condor 6
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
No detection rules found.
No public exploits indexed.
http://condor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1018http://secunia.com/advisories/37766http://secunia.com/advisories/37803http://securitytracker.com/id?1023378http://www.cs.wisc.edu/condor/manual/v7.4/8_3Stable_Release.html#SECTION00931000000000000000http://www.cs.wisc.edu/condor/security/vulnerabilities/CONDOR-2009-0001.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1688.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1689.htmlhttp://www.securityfocus.com/bid/37443https://bugzilla.redhat.com/show_bug.cgi?id=544371https://exchange.xforce.ibmcloud.com/vulnerabilities/54984http://condor-wiki.cs.wisc.edu/index.cgi/tktview?tn=1018http://secunia.com/advisories/37766http://secunia.com/advisories/37803http://securitytracker.com/id?1023378http://www.cs.wisc.edu/condor/manual/v7.4/8_3Stable_Release.html#SECTION00931000000000000000http://www.cs.wisc.edu/condor/security/vulnerabilities/CONDOR-2009-0001.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1688.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1689.htmlhttp://www.securityfocus.com/bid/37443https://bugzilla.redhat.com/show_bug.cgi?id=544371https://exchange.xforce.ibmcloud.com/vulnerabilities/54984
2009-12-23
Published