Total vulnerabilities in the database
An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.
Software | From | Fixed in |
---|---|---|
wisc / htcondor | 9.1.0 | 9.6.0 |
wisc / htcondor | 9.0.0 | 9.0.10 |
wisc / htcondor | 8.8.0 | 8.8.16 |
debian / debian_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |