CVE-2021-25311: Path Traversal
Published Jan 27, 2021
·Updated
condorcredd in HTCondor before 8.9.11 allows Directory Traversal outside the SECCREDENTIALDIRECTORYOAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.
Affected Software
1 affected component
Wisc Htcondor>=8.9.7<8.9.11
Event History
Jan 27, 2021
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-25311?
CVE-2021-25311 is considered a high-severity vulnerability due to its potential for unauthorized file creation and execution with root privileges.
2
How do I fix CVE-2021-25311?
To fix CVE-2021-25311, upgrade HTCondor to version 8.9.11 or later.
3
What type of vulnerability is CVE-2021-25311?
CVE-2021-25311 is a Directory Traversal vulnerability that allows attackers to manipulate file paths.
4
Which versions of HTCondor are affected by CVE-2021-25311?
HTCondor versions before 8.9.11, specifically 8.9.7 to 8.9.10, are affected by CVE-2021-25311.
5
What are the implications of CVE-2021-25311?
The implications of CVE-2021-25311 include the risk of remote code execution through unauthorized file placements.