CVE-2008-3424
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.65% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- condor project/condor · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/31284Broken Link, Vendor Advisory
- http://secunia.com/advisories/31423Broken Link
- http://secunia.com/advisories/31459Broken Link
- http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#sec:New-7-0-4Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0814.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0816.htmlBroken Link
- http://www.securityfocus.com/bid/30440Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020646Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44063Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00252.htmlMailing List
- http://secunia.com/advisories/31284Broken Link, Vendor Advisory
- http://secunia.com/advisories/31423Broken Link
- http://secunia.com/advisories/31459Broken Link
- http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#sec:New-7-0-4Broken Link
- http://www.redhat.com/support/errata/RHSA-2008-0814.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0816.htmlBroken Link
- http://www.securityfocus.com/bid/30440Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020646Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44063Third Party Advisory, VDB Entry
- https://www.redhat.com/archives/fedora-package-announce/2008-August/msg00252.htmlMailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.