Database/Control plane, storage & DevOps
HTCondor (S3 file transfer, daemon logs and job ClassAds): Pre-signed S3 URLs for a job's input and output are written
Impact
Pre-signed S3 URLs for a job's input and output are written into daemon logs and into the job ad. Anyone who can read the job queue or the logs gets working credentials to that tenant's private object storage - which on a GPU cluster is the training dataset and the checkpoints.
Who can reach it
Any user who can read job ClassAds (condor_q -l on another user's job in a default pool) or who has access to daemon log files on the access point.
What to do
Upgrade to HTCondor 9.0.10 or 9.5.1 and restart the daemons. Then rotate the S3 credentials used for job transfers and expire any outstanding pre-signed URLs, and purge or restrict the old daemon logs - the leaked URLs stay valid in the log files after you patch.
References
Related entries
- NetApp ONTAP SnapLock on FlexGroup volumes: An authenticated remote user modifies or deletes WORM-locked data beforeCVE-2022-23241 · NetApp ONTAP SnapLock on FlexGroup volumesHigh
- Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - Device File Transfer settings: MissingCVE-2023-25552 · Schneider Electric StruxureWare Data Center Expert (V7.9.2 and prior) - Device File Transfer settingsHigh
- Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2a: Remote unauthenticated users can bypass webCVE-2023-31424 · Brocade SANnav Management Portal web interface, before v2.3.0 and v2.2.2aHigh
- OpenPMIx (PMIx library used by Slurm and Open MPI for job launch): A race in PMIx library code that executes with UID 0CVE-2023-41915 · OpenPMIx (PMIx library used by Slurm and Open MPI for job launch)High
- Ceph RADOS Gateway (RGW): RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyoneCVE-2024-48916 · Ceph RADOS Gateway (RGW)High
- HPE Insight Remote Support (Java deserialization): Java deserialization letting an unauthenticated attacker executeCVE-2024-53673 · HPE Insight Remote Support (Java deserialization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.