Bug ID 1198143
Summary VUL-0: CVE-2021-45103: htcondor: Pre-signed URLs can be used to access private files
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/328220/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Network
Assignee cgoll@suse.com
Reporter cathy.hu@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2021-45103

An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1.
An attacker can access files stored in S3 cloud storage that a user has asked
HTCondor to transfer.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-45103
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45103
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2021-0005/
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2022-0001


You are receiving this mail because: