CVE-2010-4179
plugin: enable QUEUE_ALL_USERS_TRUSTED for Submit/Hold/Release/Remove ops
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the MRG Management Console (cumin) can submit jobs for users, which creates a trusted channel with insufficient access control that allows local users with the ability to publish to a broker to run jobs as arbitrary users via Condor QMF plug-ins.
La documentación de instalación de Red Hat Enterprise Messaging, Realtime and
Grid (MRG) v1.3 recomienda que Condor debe ser configurado para que la consola de gestion de MRG (cumin) pueda enviar tareas a los usuarios, lo que crea un canal de confianza
con insuficientes controles de acceso, lo que permite ejecutar tareas como un usuario cualquiera a usuarios locales con la
capacidad de publicar a un broker a través de las extensiones de Condor QMF.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-11-04 CVE Reserved
- 2010-12-07 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-284: Improper Access Control
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id?1024806 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/42406 | 2023-02-13 | |
http://www.redhat.com/support/errata/RHSA-2010-0921.html | 2023-02-13 | |
http://www.redhat.com/support/errata/RHSA-2010-0922.html | 2023-02-13 | |
http://www.vupen.com/english/advisories/2010/3091 | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=654856 | 2010-11-30 | |
https://access.redhat.com/security/cve/CVE-2010-4179 | 2010-11-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Enterprise Mrg Search vendor "Redhat" for product "Enterprise Mrg" | 1.3 Search vendor "Redhat" for product "Enterprise Mrg" and version "1.3" | - |
Affected
|