VDB
CVE-2008-3424
CVE-2008-3424
PUBLISHED
CVSS 7.5 HIGH
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions.
EPSS 2.65% · 84.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
2.65%
84.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| condor_project | condor | 0 |
| fedoraproject | fedora | 9 |
Timeline
- Jul 31, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
References
- 31423 third-party-advisory
- 31459 third-party-advisory
- condor-authpolicy-security-bypass(44063) vdb
- http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#sec:New-7-0-4 url
- RHSA-2008:0816 vendor-advisory
- FEDORA-2008-7205 vendor-advisory
- 1020646 vdb
- 30440 vdb
- 31284 third-party-advisory
- RHSA-2008:0814 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-3424 advisory