Torque Munge Authentication Bypass Vulnerability
BID:51224
Info
Torque Munge Authentication Bypass Vulnerability
| Bugtraq ID: | 51224 |
| Class: | Access Validation Error |
| CVE: |
CVE-2011-4925 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2012 12:00AM |
| Updated: | Apr 13 2015 09:48PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Gentoo Linux Cluster Resources Torque 2.5.8 |
| Not Vulnerable: |
Cluster Resources Torque 2.5.9 |
Discussion
Torque Munge Authentication Bypass Vulnerability
Torque is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to impersonate other users present within the torque batch system. This may lead to further attacks.
Torque is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to impersonate other users present within the torque batch system. This may lead to further attacks.
Exploit / POC
Torque Munge Authentication Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Torque Munge Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.