CVE-2021-45102: High severity htcondor vulnerability
Published Dec 16, 2021
·Updated
An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.
Affected Software
4 affected components
Wisc Htcondor=9.0.0
Wisc Htcondor=9.0.1
Wisc Htcondor=9.0.2
Wisc Htcondor=9.1.0
Event History
Dec 16, 2021
CVE Published
via MITRE·04:46 AM
Data Sourced
via MITRE·04:46 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-45102?
CVE-2021-45102 has been classified with moderate severity due to potential unauthorized access.
2
How do I fix CVE-2021-45102?
To fix CVE-2021-45102, update HTCondor to version 9.0.4 or 9.1.2 or later.
3
What versions of HTCondor are affected by CVE-2021-45102?
CVE-2021-45102 affects HTCondor versions 9.0.0 to 9.0.3 and 9.1.0.
4
What is the impact of CVE-2021-45102 on HTCondor?
The impact of CVE-2021-45102 allows users to gain unauthorized authorizations when using a SciToken.
5
Is there a workaround for CVE-2021-45102?
There is no known workaround for CVE-2021-45102; updating to a patched version is recommended.