Wisc HTCondor 8.9.4

CPE Details

Wisc HTCondor 8.9.4
8.9.4
2020-01-27
11h52 +00:00
2020-01-27
11h52 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:wisc:htcondor:8.9.4:*:*:*:*:*:*:*

Informations

Vendor

wisc

Product

htcondor

Version

8.9.4

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2021-45104 2022-04-05 23h04 +00:00 An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data.
7.4
Haute
CVE-2021-45103 2022-04-05 22h55 +00:00 An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.
8.1
Haute
CVE-2021-25312 2021-01-27 14h54 +00:00 HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.
8.8
Haute
CVE-2019-18823 2020-04-27 12h07 +00:00 HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)
9.8
Critique