CVE Vulnerabilities

CVE-2022-26110

Published: Apr 06, 2022 | Modified: Sep 03, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.

Affected Software

Name Vendor Start Version End Version
Htcondor Wisc 8.8.0 *
Htcondor Wisc 9.0.0 *
Htcondor Wisc 9.1.0 *

References