Database/Control plane, storage & DevOps
HTCondor (daemon-to-daemon channel, negotiator/startd/schedd): Secret material crosses the network in the clear when
Impact
Secret material crosses the network in the clear when weak encryption is configured or when any 8.8-or-older daemon is still in the pool. An attacker who captures it can take over another user's slot and run code as that user, and can impersonate the negotiator and startd well enough to make the schedd hand over other users' jobs.
Who can reach it
Passive capture of HTCondor traffic between daemons - so anyone on the cluster network path, including a tenant on a compute node with a promiscuous interface or a compromised switch.
What to do
Upgrade to HTCondor 9.0.10 or 9.5.1, restart all daemons, and remove every pre-9.0 daemon from the pool - the mixed-version case is what reintroduces the cleartext path. Enable strong daemon-to-daemon encryption explicitly rather than relying on defaults.
References
Related entries
- Harbor registry: P2P preheat execution logs readable/updatable by any authenticated user via job ID enumerationCVE-2022-31671 · Harbor registryHigh
- MinIO (admin server-update API): An authenticated request to the server-update admin API traverses out of the intendedCVE-2022-35919 · MinIO (admin server-update API)High
- Cisco Nexus 3000/9000 (health monitoring diagnostics): The health monitoring diagnostics subsystem on Nexus 3000 andCVE-2025-20111 · Cisco Nexus 3000/9000 (health monitoring diagnostics)High
- Confluent Kafka Python client: TLS certificate verification disabled by default toward HashiCorp Vault KMSCVE-2026-15911 · Confluent Kafka Python client (HashiCorp Vault KMS integration)High
- N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverCVE-2026-18556 · N-able N-centralHigh
- Jenkins TICS plugin: attacker-controlled build variables execute arbitrary commands on the build agentCVE-2026-84675 · Jenkins TICS plugin (build environment variable expansion into an OS command)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.