#VU63556 Inadequate Encryption Strength in HTCondor - CVE-2021-45104
Published: May 24, 2022 / Updated: May 24, 2022
HTCondor
University of Wisconsin–Madison
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists when HTCondor daemons are configured to use BLOWFISH or 3DES encryption and match password authentication is enabled. A remote attacker can capture network traffic between a condor_schedd and a condor_startd or condor_collector and gain access to sensitive information.