CVE Vulnerabilities

CVE-2012-3492

Improper Authentication

Published: Sep 28, 2012 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissions, which allows remote attackers to impersonate users by renaming a users authentication directory.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Condor Condor_project 7.6.0 (including) 7.6.0 (including)
Condor Condor_project 7.6.1 (including) 7.6.1 (including)
Condor Condor_project 7.6.2 (including) 7.6.2 (including)
Condor Condor_project 7.6.3 (including) 7.6.3 (including)
Condor Condor_project 7.6.4 (including) 7.6.4 (including)
Condor Condor_project 7.6.5 (including) 7.6.5 (including)
Condor Condor_project 7.6.6 (including) 7.6.6 (including)
Condor Condor_project 7.6.7 (including) 7.6.7 (including)
Condor Condor_project 7.6.8 (including) 7.6.8 (including)
Condor Condor_project 7.6.9 (including) 7.6.9 (including)
Condor Condor_project 7.8.0 (including) 7.8.0 (including)
Condor Condor_project 7.8.1 (including) 7.8.1 (including)
Condor Condor_project 7.8.2 (including) 7.8.2 (including)
Condor Condor_project 7.8.3 (including) 7.8.3 (including)

Potential Mitigations

References