DEBIAN-CVE-2019-18823

    Dashboard / Vulnerabilities / DEBIAN-CVE-2019-18823

    DEBIAN-CVE-2019-18823

    Published: 27 Apr 2020Last Modified: 10 Sept 2026
    Upstream:

    Summary:

    Details: HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)

    Affected packages

    Package

    Name: condor

    Purl: pkg:deb/debian/condor?arch=source&distro=trixie

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -23.2.0+dfsg-1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DEBIAN-CVE-2019-18823 | CVE-DB