Database/Control plane, storage & DevOps
HTCondor (condor_credd): condor_credd can be told to create or write files as root outside
Impact
condor_credd can be told to create or write files as root outside SEC_CREDENTIAL_DIRECTORY_OAUTH. The advisory's own example is planting a file under /etc that later gets executed - so this is a path-traversal-to-root on the credential daemon's host, which is normally the access point of the pool.
Who can reach it
An authenticated pool user who can talk to a running condor_credd.
What to do
Upgrade to HTCondor 8.9.11 or later and restart condor_credd. If you are not using OAuth credential handling, do not run credd at all. After patching, check /etc and the systemd unit directories on credd hosts for files you did not put there.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.