CVE-2014-8126Improper Input Validation in Htcondor

Severity
8.8HIGHNVD
EPSS
1.5%
top 19.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 31
Latest updateMay 17

Description

The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDwisc/htcondor< 8.2.6
CVEListV5htcondor/htcondorbefore 8.2.6
Debiancondor_project/condor< 8.2.3~dfsg.1-6+1
Ubuntucondor_project/condor< 8.0.5~dfsg.1-1ubuntu1+esm1+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-4cwh-h77q-9rqx: The scheduler in HTCondor before 82022-05-17
OSV
condor vulnerabilities2021-03-15
OSV
CVE-2014-8126: The scheduler in HTCondor before 82020-01-31
CVEList
CVE-2014-8126: The scheduler in HTCondor before 82020-01-31

📋Vendor Advisories

3
Ubuntu
HTCondor vulnerabilities2021-03-15
Red Hat
condor: mailx invocation enables code execution as condor user2015-01-12
Debian
CVE-2014-8126: condor - The scheduler in HTCondor before 8.2.6 allows remote authenticated users to exec...2014

💬Community

2
Bugzilla
CVE-2014-8126 condor: mailx invocation enables code execution as condor user [fedora-all]2015-01-12
Bugzilla
CVE-2014-8126 condor: mailx invocation enables code execution as condor user2014-12-02
CVE-2014-8126 — Improper Input Validation in Htcondor | cvebase