Database/Control plane, storage & DevOps
HTCondor (daemon-to-daemon channel, negotiator/startd/schedd): Secret material crosses the network in the clear when
Impact
Secret material crosses the network in the clear when weak encryption is configured or when any 8.8-or-older daemon is still in the pool. An attacker who captures it can take over another user's slot and run code as that user, and can impersonate the negotiator and startd well enough to make the schedd hand over other users' jobs.
Who can reach it
Passive capture of HTCondor traffic between daemons - so anyone on the cluster network path, including a tenant on a compute node with a promiscuous interface or a compromised switch.
What to do
Upgrade to HTCondor 9.0.10 or 9.5.1, restart all daemons, and remove every pre-9.0 daemon from the pool - the mixed-version case is what reintroduces the cleartext path. Enable strong daemon-to-daemon encryption explicitly rather than relying on defaults.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.