First published: Tue Mar 29 2022(Updated: )
An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/condor | <=8.6.8~dfsg.1-2 | 8.6.8~dfsg.1-2+deb10u1 |
Wisc Htcondor | >=8.8.0<8.8.16 | |
Wisc Htcondor | >=9.0.0<9.0.10 | |
Wisc Htcondor | >=9.1.0<9.6.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.