Database/Control plane, storage & DevOps
HTCondor (IDToken authorization restrictions): MULTI-TENANT ISOLATION: The per-token authorization restrictions
Impact
MULTI-TENANT ISOLATION: The per-token authorization restrictions attached with condor_token_create -authz are not enforced. A token you deliberately minted as read-only, or scoped to one operation, performs everything the underlying identity is entitled to. Sites that use restricted tokens to hand limited access to a partner or a CI system have a boundary that does not exist.
Who can reach it
Any holder of an IDToken that the target daemon can validate. The attacker does not need to be permitted by the daemon's configured authorization policy for the restriction bypass itself.
What to do
Upgrade to HTCondor 23.0.22, 23.10.22, 24.0.6 or 24.6.1 and restart the daemons. Then inventory every token issued with -authz, or approved via condor_token_request_approve, and reissue them - each one has been operating as an unrestricted token for its identity.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.