CVE-2019-18823: Critical severity htcondor vulnerability
HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condorschedd. (For example to submit or remove jobs)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18823?
CVE-2019-18823 has been identified as a high severity vulnerability due to its incorrect access control.
How do I fix CVE-2019-18823?
To fix CVE-2019-18823, upgrade HTCondor to version 8.6.8~dfsg.1-2+deb10u1 or later.
What versions of HTCondor are affected by CVE-2019-18823?
CVE-2019-18823 affects HTCondor versions up to and including 8.8.6 and development series up to 8.9.4.
What is the nature of the access control issue in CVE-2019-18823?
The access control issue in CVE-2019-18823 allows jobs to be submitted using a different authentication method than the one specified by the administrator.
Which platforms are impacted by CVE-2019-18823?
CVE-2019-18823 impacts multiple platforms including Debian and Fedora that utilize vulnerable versions of HTCondor.