GPU VulnDB

Database/Control plane, storage & DevOps

HTCondor (IDTOKENS authentication): A flaw in IDTOKENS lets a user authenticate as another user or as the condor

CVE-2021-25312Control plane, storage & DevOpsHTCONDOR-2021-0001curated

Impact

A flaw in IDTOKENS lets a user authenticate as another user or as the condor service itself. Once you are the condor service you own the scheduler - you decide whose jobs run on which GPUs and you can submit work under any tenant's identity.

Who can reach it

A user who can authenticate to an HTCondor daemon with IDTOKENS, which is the recommended modern method and therefore widely enabled.

What to do

Upgrade to HTCondor 8.9.11 or later and restart all daemons. Rotate the IDTOKEN signing keys after upgrading and reissue tokens - a token minted while the flaw was live cannot be distinguished from a legitimate one.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.