HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)
{ "binaries": [ { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "condor" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "condor-annex-ec2" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "condor-dev" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "condor-kbdd" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "condor-test" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "condor-upgrade-checks" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "condor-vm-gahp" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "htcondor" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "htcondor-annex-ec2" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "htcondor-dev" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "htcondor-test" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "htcondor-upgrade-checks" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "minicondor" }, { "binary_version": "23.4.0+dfsg-1ubuntu4.1", "binary_name": "minihtcondor" } ] }
{ "binaries": [ { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "condor" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "condor-annex-ec2" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "condor-dev" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "condor-kbdd" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "condor-test" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "condor-upgrade-checks" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "condor-vm-gahp" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "htcondor" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "htcondor-annex-ec2" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "htcondor-dev" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "htcondor-test" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "htcondor-upgrade-checks" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "minicondor" }, { "binary_version": "23.6.2+dfsg-2build1", "binary_name": "minihtcondor" } ] }
{ "binaries": [ { "binary_version": "8.0.5~dfsg.1-1ubuntu1+esm1", "binary_name": "htcondor" }, { "binary_version": "8.0.5~dfsg.1-1ubuntu1+esm1", "binary_name": "htcondor-dev" }, { "binary_version": "8.0.5~dfsg.1-1ubuntu1+esm1", "binary_name": "libclassad-dev" }, { "binary_version": "8.0.5~dfsg.1-1ubuntu1+esm1", "binary_name": "libclassad5" } ] }
{ "binaries": [ { "binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1", "binary_name": "condor" }, { "binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1", "binary_name": "condor-dev" }, { "binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1", "binary_name": "htcondor" }, { "binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1", "binary_name": "htcondor-dev" }, { "binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1", "binary_name": "libclassad-dev" }, { "binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1", "binary_name": "libclassad7" } ] }
{ "binaries": [ { "binary_version": "8.6.8~dfsg.1-2", "binary_name": "htcondor" }, { "binary_version": "8.6.8~dfsg.1-2", "binary_name": "htcondor-dev" }, { "binary_version": "8.6.8~dfsg.1-2", "binary_name": "libclassad-dev" }, { "binary_version": "8.6.8~dfsg.1-2", "binary_name": "libclassad8" } ] }
{ "binaries": [ { "binary_version": "8.6.8~dfsg.1-2ubuntu1", "binary_name": "htcondor" }, { "binary_version": "8.6.8~dfsg.1-2ubuntu1", "binary_name": "htcondor-dev" }, { "binary_version": "8.6.8~dfsg.1-2ubuntu1", "binary_name": "libclassad-dev" }, { "binary_version": "8.6.8~dfsg.1-2ubuntu1", "binary_name": "libclassad8" } ] }