GPU VulnDB

Database/Control plane, storage & DevOps

HTCondor (condor_credd): condor_credd can be told to create or write files as root outside

CVE-2021-25311Control plane, storage & DevOpsHTCONDOR-2021-0002curated

Impact

condor_credd can be told to create or write files as root outside SEC_CREDENTIAL_DIRECTORY_OAUTH. The advisory's own example is planting a file under /etc that later gets executed - so this is a path-traversal-to-root on the credential daemon's host, which is normally the access point of the pool.

Who can reach it

An authenticated pool user who can talk to a running condor_credd.

What to do

Upgrade to HTCondor 8.9.11 or later and restart condor_credd. If you are not using OAuth credential handling, do not run credd at all. After patching, check /etc and the systemd unit directories on credd hosts for files you did not put there.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.