CVE-2021-25312: High severity htcondor vulnerability
Published Jan 27, 2021
·Updated
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.
Affected Software
1 affected component
Wisc Htcondor>=8.9.2<8.9.11
Event History
Jan 27, 2021
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-25312?
CVE-2021-25312 is considered a high severity vulnerability due to unauthorized job submission capabilities.
2
How do I fix CVE-2021-25312?
To fix CVE-2021-25312, upgrade HTCondor to version 8.9.11 or later.
3
What versions of HTCondor are affected by CVE-2021-25312?
HTCondor versions prior to 8.9.11, specifically from 8.9.2 to 8.9.10, are affected by CVE-2021-25312.
4
What kind of attack can exploit CVE-2021-25312?
An attacker can exploit CVE-2021-25312 to submit jobs as another user, potentially leading to privilege escalation.
5
Is CVE-2021-25312 related to user authentication?
Yes, CVE-2021-25312 involves a flaw in the IDTOKENS authentication method allowing cross-user job submission.