CVE Vulnerabilities

CVE-2019-18823

Improper Authentication

Published: Apr 27, 2020 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Htcondor Wisc 8.8.0 (including) 8.8.6 (including)
Htcondor Wisc 8.9.0 (including) 8.9.4 (including)
Condor Ubuntu bionic *
Condor Ubuntu trusty *
Condor Ubuntu trusty/esm *
Condor Ubuntu xenial *

Potential Mitigations

References