CVE Vulnerabilities

CVE-2022-26110

Published: Apr 06, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.

Affected Software

Name Vendor Start Version End Version
Htcondor Wisc 8.8.0 (including) 8.8.16 (excluding)
Htcondor Wisc 9.0.0 (including) 9.0.10 (excluding)
Htcondor Wisc 9.1.0 (including) 9.6.0 (excluding)
Condor Ubuntu bionic *
Condor Ubuntu trusty *
Condor Ubuntu trusty/esm *
Condor Ubuntu xenial *

References