CVE-2025-30093
- EPSS 0.04%
- Published 27.03.2025 00:00:00
- Last modified 30.04.2025 16:43:08
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.
CVE-2021-45104
- EPSS 0.12%
- Published 06.04.2022 02:15:08
- Last modified 21.11.2024 06:31:58
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data.
CVE-2022-26110
- EPSS 0.32%
- Published 06.04.2022 02:15:08
- Last modified 21.11.2024 06:53:26
An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands ...
CVE-2021-45103
- EPSS 0.28%
- Published 06.04.2022 01:15:06
- Last modified 21.11.2024 06:31:57
An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.
CVE-2021-45101
- EPSS 0.36%
- Published 16.12.2021 05:15:08
- Last modified 21.11.2024 06:31:57
An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-line tools, a user with only READ access to an HTCondor SchedD or Collector daemon can discover secrets that could allow them to con...
CVE-2021-45102
- EPSS 0.34%
- Published 16.12.2021 05:15:08
- Last modified 21.11.2024 06:31:57
An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.
CVE-2021-25311
- EPSS 2.77%
- Published 27.01.2021 16:15:13
- Last modified 21.11.2024 05:54:43
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.
CVE-2021-25312
- EPSS 0.46%
- Published 27.01.2021 16:15:13
- Last modified 21.11.2024 05:54:43
HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method.
CVE-2019-18823
- EPSS 2.82%
- Published 27.04.2020 15:15:12
- Last modified 21.11.2024 04:33:38
HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configu...
CVE-2014-8126
- EPSS 1.45%
- Published 31.01.2020 22:15:10
- Last modified 21.11.2024 02:18:36
The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.