cbcvebase.
CVE-2014-8126
published 2020-01-31

CVE-2014-8126: The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.

PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.08%
86.2th percentile
The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.

Affected

7 ranges
VendorProductVersion rangeFixed in
condor_projectcondor>= 0 < 8.2.3~dfsg.1-68.2.3~dfsg.1-6
condor_projectcondor>= 0 < 8.2.3~dfsg.1-68.2.3~dfsg.1-6
condor_projectcondor>= 0 < 8.0.5~dfsg.1-1ubuntu1+esm18.0.5~dfsg.1-1ubuntu1+esm1
condor_projectcondor>= 0 < 8.4.2~dfsg.1-1ubuntu0.1~esm18.4.2~dfsg.1-1ubuntu0.1~esm1
debiancondor< condor 8.2.3~dfsg.1-6 (forky)condor 8.2.3~dfsg.1-6 (forky)
htcondorhtcondor
wischtcondor< 8.2.68.2.6

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.