Database/Control plane, storage & DevOps
HTCondor (SciTokens authentication): A SciToken is granted more authorization than the token's scopes should permit.
CVE-2021-45102Control plane, storage & DevOpsHTCONDOR-2021-0004curated
Impact
A SciToken is granted more authorization than the token's scopes should permit. Federated sites use SciTokens precisely to bound what a remote submitter may do, so this turns a deliberately narrow delegation into a wide one.
Who can reach it
Anyone holding a valid SciToken accepted by the pool, including remote federation partners.
What to do
Upgrade to HTCondor 9.0.4 or 9.1.2 and restart the daemons. Re-derive your authorization policy from the token issuer's scopes afterwards rather than assuming the previous mapping was enforced.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.