CVE-2012-3491: Medium severity Condor Project Condor vulnerability
Florian Weimer of the Red Hat Product Security Team discovered that the ability to abort a job in Condor only required WRITE authorization, instead of a combination of WRITE authorization and job ownership. This could allow an authenticated attacker to bypass intended restrictions and abort any idle job on the system.
Other sources
src/condorschedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3491?
CVE-2012-3491 has a medium severity rating due to its potential impact on job management in Condor.
How do I fix CVE-2012-3491?
To fix CVE-2012-3491, upgrade to Condor version 7.6.10 or 7.8.4 or later.
Who discovered CVE-2012-3491?
CVE-2012-3491 was discovered by Florian Weimer from the Red Hat Product Security Team.
What does CVE-2012-3491 exploit?
CVE-2012-3491 exploits an authorization flaw that allows an authenticated user to abort any idle job without proper ownership.
Which versions of Condor are affected by CVE-2012-3491?
CVE-2012-3491 affects Condor versions from 7.6.0 to 7.6.9 and 7.8.0 to 7.8.3.