Database/Control plane, storage & DevOps
HTCondor (SciTokens authentication): A SciToken is granted more authorization than the token's scopes should permit.
CVSS 8.8CVE-2021-45102Control plane, storage & DevOpsHTCONDOR-2021-0004curated
Impact
A SciToken is granted more authorization than the token's scopes should permit. Federated sites use SciTokens precisely to bound what a remote submitter may do, so this turns a deliberately narrow delegation into a wide one.
Who can reach it
Anyone holding a valid SciToken accepted by the pool, including remote federation partners.
What to do
Upgrade to HTCondor 9.0.4 or 9.1.2 and restart the daemons. Re-derive your authorization policy from the token issuer's scopes afterwards rather than assuming the previous mapping was enforced.
References
Related entries
- PostgreSQL: Autovacuum, REINDEX, CLUSTER etc. apply protections too lateCVE-2022-1552 · PostgreSQLHigh
- Samba (AD DC): KDC and kpasswd share keysCVE-2022-2031 · Samba (AD DC)High
- Intel Data Center Manager: Improper access control in Data Center Manager lets an unauthenticated attackerCVE-2022-23182 · Intel Data Center ManagerHigh
- MinIO: Non-admin user can create service accounts for root/admin users and assume their policiesCVE-2022-24842 · MinIOHigh
- HTCondor (CLAIMTOBE authentication method): Once a user has authenticated to a daemon with CLAIMTOBE - a method thatCVE-2022-26110 · HTCondor (CLAIMTOBE authentication method)High
- Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5: Unauthenticated program writesCVE-2022-30243 · Honeywell Alerton Visual Logic, Ascent Control Module (ACM) and Compass 1.6.5High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.