VulnerabilityModified
CVE-2011-4925
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.
MEDIUM 4.9EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors.
- CVSS 2.0
- 4.9 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cluster resources/torque resource manager · clusterresources/torque resource manager
- Source
- secalert@redhat.com
References
- http://openwall.com/lists/oss-security/2012/01/05/1
- http://openwall.com/lists/oss-security/2012/01/05/9Patch
- http://secunia.com/advisories/47381Vendor Advisory
- http://www.adaptivecomputing.com/resources/docs/torque/3-0-3/changelog.php#259
- http://www.securityfocus.com/bid/51224
- http://openwall.com/lists/oss-security/2012/01/05/1
- http://openwall.com/lists/oss-security/2012/01/05/9Patch
- http://secunia.com/advisories/47381Vendor Advisory
- http://www.adaptivecomputing.com/resources/docs/torque/3-0-3/changelog.php#259
- http://www.securityfocus.com/bid/51224
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.