CVE-2022-26110
Debian Security Advisory 5144-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.
Se ha detectado un problema en HTCondor versiones 8.8.x anteriores a 8.8.16, versiones 9.0.x anteriores a 9.0.10 y versiones 9.1.x anteriores a 9.6.0. Cuando un usuario es autenticado en un demonio de HTCondor por medio del método CLAIMTOBE, el usuario puede hacerse pasar por cualquier entidad cuando emite comandos adicionales a ese demonio
Several flaws have been discovered in HTCondor, a distributed workload management system, which allow users with only READ access to any daemon to use a different authentication method than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user and submit or remove jobs.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-25 CVE Reserved
- 2022-04-06 CVE Published
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2022/04/msg00016.html | Mailing List |
|
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2022-0003 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2022/dsa-5144 | 2022-09-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wisc Search vendor "Wisc" | Htcondor Search vendor "Wisc" for product "Htcondor" | >= 8.8.0 < 8.8.16 Search vendor "Wisc" for product "Htcondor" and version " >= 8.8.0 < 8.8.16" | - |
Affected
| ||||||
Wisc Search vendor "Wisc" | Htcondor Search vendor "Wisc" for product "Htcondor" | >= 9.0.0 < 9.0.10 Search vendor "Wisc" for product "Htcondor" and version " >= 9.0.0 < 9.0.10" | - |
Affected
| ||||||
Wisc Search vendor "Wisc" | Htcondor Search vendor "Wisc" for product "Htcondor" | >= 9.1.0 < 9.6.0 Search vendor "Wisc" for product "Htcondor" and version " >= 9.1.0 < 9.6.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|