PT-2008-4827 · Htcondor · Condor

Published

2008-07-31

·

Updated

2024-01-12

·

CVE-2008-3424

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Condor versions prior to 7.0.4
Description The issue is related to the improper handling of wildcards in certain configuration variables, specifically ALLOW WRITE, DENY WRITE, HOSTALLOW WRITE, and HOSTDENY WRITE, within authorization policy lists. This might allow remote attackers to bypass intended access restrictions.
Recommendations For versions prior to 7.0.4, update to version 7.0.4 or later to resolve the issue. As a temporary workaround, consider reviewing and restricting the use of wildcards in the ALLOW WRITE, DENY WRITE, HOSTALLOW WRITE, and HOSTDENY WRITE configuration variables to minimize the risk of exploitation.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2008-3424
RHSA-2008:0814
RHSA-2008:0816

Affected Products

Condor