GPU VulnDB

Database/Control plane, storage & DevOps

HTCondor (condor_schedd, condor_collector): MULTI-TENANT ISOLATION: A user with nothing more than READ access to the

CVE-2021-45101Control plane, storage & DevOpsHTCONDOR-2021-0003curated

Impact

MULTI-TENANT ISOLATION: A user with nothing more than READ access to the schedd or collector can pull out secrets - using stock command-line tools, no exploit development - that let them control other users' jobs and read their data. READ is the permission level sites hand out freely for monitoring, so the attacker population is broad.

Who can reach it

Any principal granted ALLOW_READ on the schedd or collector, using ordinary condor_q and condor_status style commands.

What to do

Upgrade to HTCondor 8.8.15, 9.0.4 or 9.1.2 and restart the daemons. Review who actually holds READ on the collector - on many pools it is set to */* for convenience.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.