First published: Wed Jan 27 2021(Updated: )
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HTCondor | >=8.9.2<8.9.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25312 is considered a high severity vulnerability due to unauthorized job submission capabilities.
To fix CVE-2021-25312, upgrade HTCondor to version 8.9.11 or later.
HTCondor versions prior to 8.9.11, specifically from 8.9.2 to 8.9.10, are affected by CVE-2021-25312.
An attacker can exploit CVE-2021-25312 to submit jobs as another user, potentially leading to privilege escalation.
Yes, CVE-2021-25312 involves a flaw in the IDTOKENS authentication method allowing cross-user job submission.