CVE-2022-26110
HIGH8.8EPSS 0.45%condor - security update
發布日:2022/4/6修改日:2026/4/28
描述
An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.
受影響套件(2)
- Debian/condorfrom 0, < 23.2.0+dfsg-1
- Debian/condorfrom 0, < 8.4.11~dfsg.1-1+deb9u2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |