CVE-2021-45103: High severity htcondor vulnerability
Published Apr 6, 2022
·Updated
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.
Affected Software
2 affected components
Wisc Htcondor>=8.9.4<9.0.10
Wisc Htcondor>=9.1.0<9.6.0
Event History
Apr 6, 2022
CVE Published
via MITRE·12:55 AM
Data Sourced
via MITRE·12:55 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-45103?
CVE-2021-45103 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2021-45103?
To fix CVE-2021-45103, upgrade HTCondor to version 9.0.10 or later, or to version 9.5.1 or later.
3
What is the impact of CVE-2021-45103?
The impact of CVE-2021-45103 allows an attacker to access sensitive S3 cloud storage files during HTCondor transfers.
4
Which versions of HTCondor are affected by CVE-2021-45103?
HTCondor versions 9.0.x before 9.0.10 and 9.1.x before 9.5.1 are affected by CVE-2021-45103.
5
Is there a workaround for CVE-2021-45103?
There are no known workarounds for CVE-2021-45103, so upgrading is recommended.