cbcvebase.
CVE-2022-26110
published 2022-04-06

CVE-2022-26110: An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.

Affected

8 ranges
VendorProductVersion rangeFixed in
condor_projectcondor>= 0 < 23.2.0+dfsg-123.2.0+dfsg-1
condor_projectcondor>= 0 < 23.2.0+dfsg-123.2.0+dfsg-1
debiancondor< condor 23.2.0+dfsg-1 (forky)condor 23.2.0+dfsg-1 (forky)
debiandebian_linux
debiandebian_linux
wischtcondor>= 8.8.0 < 8.8.168.8.16
wischtcondor>= 9.0.0 < 9.0.109.0.10
wischtcondor>= 9.1.0 < 9.6.09.6.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH