An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Htcondor | Wisc | 8.8.0 (including) | 8.8.16 (excluding) |
Htcondor | Wisc | 9.0.0 (including) | 9.0.10 (excluding) |
Htcondor | Wisc | 9.1.0 (including) | 9.6.0 (excluding) |
Condor | Ubuntu | bionic | * |
Condor | Ubuntu | trusty | * |
Condor | Ubuntu | trusty/esm | * |
Condor | Ubuntu | xenial | * |