First published: Wed Jan 27 2021(Updated: )
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HTCondor | >=8.9.7<8.9.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25311 is considered a high-severity vulnerability due to its potential for unauthorized file creation and execution with root privileges.
To fix CVE-2021-25311, upgrade HTCondor to version 8.9.11 or later.
CVE-2021-25311 is a Directory Traversal vulnerability that allows attackers to manipulate file paths.
HTCondor versions before 8.9.11, specifically 8.9.7 to 8.9.10, are affected by CVE-2021-25311.
The implications of CVE-2021-25311 include the risk of remote code execution through unauthorized file placements.