Lucene search

K
osvGoogleOSV:CVE-2022-26110
HistoryApr 06, 2022 - 2:15 a.m.

CVE-2022-26110

2022-04-0602:15:08
Google
osv.dev
7
htcondor
unauthorized access
entity impersonation
cve-2022-26110

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

42.9%

An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

42.9%