Database/Control plane, storage & DevOps
HTCondor (condor_credd): condor_credd can be told to create or write files as root outside
Impact
condor_credd can be told to create or write files as root outside SEC_CREDENTIAL_DIRECTORY_OAUTH. The advisory's own example is planting a file under /etc that later gets executed - so this is a path-traversal-to-root on the credential daemon's host, which is normally the access point of the pool.
Who can reach it
An authenticated pool user who can talk to a running condor_credd.
What to do
Upgrade to HTCondor 8.9.11 or later and restart condor_credd. If you are not using OAuth credential handling, do not run credd at all. After patching, check /etc and the systemd unit directories on credd hosts for files you did not put there.
References
Related entries
- RKE / Rancher (k8s control plane): full-cluster-state configmap in kube-system readable by non-adminsCVE-2023-32191 · RKE / Rancher (k8s control plane)Critical
- VMware Aria Automation (missing access control): An authenticated user reaches remote organizations and workflows theyCVE-2023-34063 · VMware Aria Automation (missing access control)Critical
- Cisco Nexus Dashboard Fabric Controller (REST API / web UI): A low-privileged NDFC userCVE-2024-20432 · Cisco Nexus Dashboard Fabric Controller (REST API / web UI)Critical
- Zabbix: SQL injection in CUser::addRelatedObjects reachable by ANY non-admin account with API accessCVE-2024-42327 · ZabbixCritical
- Grafana: SQL Expressions passes user input to duckdb unsanitizedCVE-2024-9264 · GrafanaCritical
- Redis: "RediShell" - authenticated user crafts a Lua script to trigger a use-after-freeCVE-2025-49844 · RedisCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.