CVE Vulnerabilities

CVE-2022-26110

Published: Apr 06, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.

Affected Software

NameVendorStart VersionEnd Version
HtcondorWisc8.8.0 (including)8.8.16 (excluding)
HtcondorWisc9.0.0 (including)9.0.10 (excluding)
HtcondorWisc9.1.0 (including)9.6.0 (excluding)
CondorUbuntubionic*
CondorUbuntufocal*
CondorUbuntuoracular*
CondorUbuntuplucky*
CondorUbuntutrusty*
CondorUbuntutrusty/esm*
CondorUbuntuxenial*

References