Lucene search

K
cve[email protected]CVE-2008-3830
HistoryOct 08, 2008 - 10:00 p.m.

CVE-2008-3830

2008-10-0822:00:01
CWE-264
web.nvd.nist.gov
24
condor
access restrictions
cve-2008-3830
netmasks
configuration
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.7%

Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers to bypass intended access restrictions.

Affected configurations

NVD
Node
condor_projectcondorRange7.0.4
OR
condor_projectcondorMatch6.8.0
OR
condor_projectcondorMatch6.8.1
OR
condor_projectcondorMatch6.8.2
OR
condor_projectcondorMatch6.8.3
OR
condor_projectcondorMatch6.8.4
OR
condor_projectcondorMatch6.8.5
OR
condor_projectcondorMatch6.8.6
OR
condor_projectcondorMatch6.8.7
OR
condor_projectcondorMatch6.8.8
OR
condor_projectcondorMatch6.8.9
OR
condor_projectcondorMatch7.0.0
OR
condor_projectcondorMatch7.0.1
OR
condor_projectcondorMatch7.0.2
OR
condor_projectcondorMatch7.0.3

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.7%