Database/Control plane, storage & DevOps
HTCondor (IDTOKENS authentication): A flaw in IDTOKENS lets a user authenticate as another user or as the condor
Impact
A flaw in IDTOKENS lets a user authenticate as another user or as the condor service itself. Once you are the condor service you own the scheduler - you decide whose jobs run on which GPUs and you can submit work under any tenant's identity.
Who can reach it
A user who can authenticate to an HTCondor daemon with IDTOKENS, which is the recommended modern method and therefore widely enabled.
What to do
Upgrade to HTCondor 8.9.11 or later and restart all daemons. Rotate the IDTOKEN signing keys after upgrading and reissue tokens - a token minted while the flaw was live cannot be distinguished from a legitimate one.
References
Related entries
- linuxptp / ptp4l (PTP message forwarding): A missing length check when ptp4l forwards a PTP message between ports leaksCVE-2021-3570 · linuxptp / ptp4l (PTP message forwarding)High
- Terraform Enterprise: Missing authorization on a subset of run-token API requestsCVE-2021-36230 · Terraform EnterpriseHigh
- AMD System Management Mode (SMM) interrupt handler: A flaw in the AMD SMM interrupt handler lets a high-privilegeCVE-2021-39298 · AMD System Management Mode (SMM) interrupt handlerHigh
- MinIO (IAM policy engine): A regular user can step outside the policy restrictions applied to them, reaching operationsCVE-2021-41137 · MinIO (IAM policy engine)High
- MinIO: Hand-crafted admin API call updates a user's policyCVE-2021-43858 · MinIOHigh
- Samba (SMB gateway): Out-of-bounds heap read/write in vfs_fruitCVE-2021-44142 · Samba (SMB gateway)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.