An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2021-0005/ | broken link |
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2022-0001 | mitigation vendor advisory |