An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.
2021-12-16T05:15:08.917
2024-11-21T06:31:57.717
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | wisc | htcondor | 9.0.0 | Yes |
Application | wisc | htcondor | 9.0.1 | Yes |
Application | wisc | htcondor | 9.0.2 | Yes |
Application | wisc | htcondor | 9.1.0 | Yes |