The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.
2014-06-06T14:55:03.370
2025-04-12T10:46:40.837
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | condor_project | condor | 7.9.0 | Yes |
Application | condor_project | condor | 7.8.0 | Yes |
Application | condor_project | condor | 7.8.1 | Yes |
Application | condor_project | condor | 7.8.2 | Yes |
Application | condor_project | condor | 7.8.3 | Yes |
Application | condor_project | condor | 7.8.4 | Yes |
Application | condor_project | condor | 7.7.3 | Yes |
Application | condor_project | condor | 7.7.4 | Yes |
Application | condor_project | condor | 7.7.5 | Yes |
Application | condor_project | condor | 7.7.6 | Yes |