cbcvebase.
CVE-2022-26110
published 2022-04-06

CVE-2022-26110: An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the…

PriorityP347high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.40%
69.5th percentile
An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.

Affected

8 ranges
VendorProductVersion rangeFixed in
condor_projectcondor>= 0 < 23.2.0+dfsg-123.2.0+dfsg-1
condor_projectcondor>= 0 < 23.2.0+dfsg-123.2.0+dfsg-1
debiancondor< condor 23.2.0+dfsg-1 (forky)condor 23.2.0+dfsg-1 (forky)
debiandebian_linux
debiandebian_linux
wischtcondor>= 8.8.0 < 8.8.168.8.16
wischtcondor>= 9.0.0 < 9.0.109.0.10
wischtcondor>= 9.1.0 < 9.6.09.6.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.