Improper Authorization in HTCondor - CVE-2022-26110
Published: May 24, 2022
Vulnerability identifier: #VU63554
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26110
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper authorization when a user authenticates to an HTCondor daemon via the CLAIMTOBE method. A remote user can impersonate any entity when issuing additional commands to that daemon and escalate privileges within the application.
The vulnerability exists due to improper authorization when a user authenticates to an HTCondor daemon via the CLAIMTOBE method. A remote user can impersonate any entity when issuing additional commands to that daemon and escalate privileges within the application.
Affected software
HTCondor
condor (Debian package)
condor (Debian package)
How to mitigate CVE-2022-26110
Install updates from vendor's website.
HTCondor - addressed in versions 8.8.16, 9.0.10, 9.6.0
condor (Debian package) - update to 8.6.8~dfsg.1-2+deb10u1
condor (Debian package) - update to 8.6.8~dfsg.1-2+deb10u1