HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)
{
"binaries": [
{
"binary_version": "8.6.8~dfsg.1-2",
"binary_name": "htcondor"
},
{
"binary_version": "8.6.8~dfsg.1-2",
"binary_name": "htcondor-dev"
},
{
"binary_version": "8.6.8~dfsg.1-2",
"binary_name": "libclassad-dev"
},
{
"binary_version": "8.6.8~dfsg.1-2",
"binary_name": "libclassad8"
}
]
}{
"binaries": [
{
"binary_version": "8.6.8~dfsg.1-2ubuntu1",
"binary_name": "htcondor"
},
{
"binary_version": "8.6.8~dfsg.1-2ubuntu1",
"binary_name": "htcondor-dev"
},
{
"binary_version": "8.6.8~dfsg.1-2ubuntu1",
"binary_name": "libclassad-dev"
},
{
"binary_version": "8.6.8~dfsg.1-2ubuntu1",
"binary_name": "libclassad8"
}
]
}{
"binaries": [
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "condor"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "condor-annex-ec2"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "condor-dev"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "condor-kbdd"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "condor-test"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "condor-upgrade-checks"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "condor-vm-gahp"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "htcondor"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "htcondor-annex-ec2"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "htcondor-dev"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "htcondor-test"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "htcondor-upgrade-checks"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "minicondor"
},
{
"binary_version": "23.4.0+dfsg-1ubuntu4.1",
"binary_name": "minihtcondor"
}
]
}{
"binaries": [
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "condor"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "condor-annex-ec2"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "condor-dev"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "condor-kbdd"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "condor-test"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "condor-upgrade-checks"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "condor-vm-gahp"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "htcondor"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "htcondor-annex-ec2"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "htcondor-dev"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "htcondor-test"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "htcondor-upgrade-checks"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "minicondor"
},
{
"binary_version": "23.6.2+dfsg-2build1",
"binary_name": "minihtcondor"
}
]
}{
"binaries": [
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "condor"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "condor-annex-ec2"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "condor-dev"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "condor-kbdd"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "condor-test"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "condor-upgrade-checks"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "condor-vm-gahp"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "htcondor"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "htcondor-annex-ec2"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "htcondor-dev"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "htcondor-test"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "htcondor-upgrade-checks"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "minicondor"
},
{
"binary_version": "23.9.6+dfsg-2.1build2",
"binary_name": "minihtcondor"
}
]
}{
"binaries": [
{
"binary_version": "8.0.5~dfsg.1-1ubuntu1+esm1",
"binary_name": "htcondor"
},
{
"binary_version": "8.0.5~dfsg.1-1ubuntu1+esm1",
"binary_name": "htcondor-dev"
},
{
"binary_version": "8.0.5~dfsg.1-1ubuntu1+esm1",
"binary_name": "libclassad-dev"
},
{
"binary_version": "8.0.5~dfsg.1-1ubuntu1+esm1",
"binary_name": "libclassad5"
}
]
}{
"binaries": [
{
"binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1",
"binary_name": "condor"
},
{
"binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1",
"binary_name": "condor-dev"
},
{
"binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1",
"binary_name": "htcondor"
},
{
"binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1",
"binary_name": "htcondor-dev"
},
{
"binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1",
"binary_name": "libclassad-dev"
},
{
"binary_version": "8.4.2~dfsg.1-1ubuntu0.1~esm1",
"binary_name": "libclassad7"
}
]
}