Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.10% | — | Wisc HtcondorAI | 30/11/2025 | 17/6/2026 | HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed in 24.12.14, 25.0.3, and 25.3.1. The earliest affected version is 24.7.3. | |
| Analizada | Alta (8.1) | 0.35% | — | Wisc Htcondor | 27/3/2025 | 17/6/2026 | HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions. | |
| Modificada | Alta (8.8) | 1.5% | — | Wisc HtcondorDebian Linux | 6/4/2022 | 17/6/2026 | An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon. | |
| Modificada | Alta (7.4) | 0.59% | — | Wisc Htcondor | 6/4/2022 | 17/6/2026 | An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor network data can interfere with users' jobs and data. | |
| Modificada | Alta (8.1) | 0.92% | — | Wisc Htcondor | 6/4/2022 | 17/6/2026 | An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user has asked HTCondor to transfer. | |
| Modificada | Alta (8.8) | 0.90% | — | Wisc Htcondor | 16/12/2021 | 17/6/2026 | An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow. | |
| Modificada | Alta (8.1) | 0.94% | — | Wisc Htcondor | 16/12/2021 | 17/6/2026 | An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-line tools, a user with only READ access to an HTCondor SchedD or Collector daemon can discover secrets that could allow them to control other users' jobs and/or read their data. | |
| Modificada | Alta (8.8) | 1.0% | — | Wisc Htcondor | 27/1/2021 | 17/6/2026 | HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS authentication method. | |
| Modificada | Crítica (9.9) | 3.2% | — | Wisc Htcondor | 27/1/2021 | 17/6/2026 | condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root. | |
| Modificada | Crítica (9.8) | 2.8% | — | Wisc HtcondorFedoraproject FedoraDebian Linux | 27/4/2020 | 17/6/2026 | HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is… | |
| Modificada | Alta (8.8) | 3.1% | — | Wisc Htcondor | 31/1/2020 | 17/6/2026 | The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code. | |
| Modificada | Alta (8.8) | 3.6% | — | Wisc Htcondor | 9/1/2020 | 16/6/2026 | The (1) my_popenv_impl and (2) my_spawnv functions in src/condor_utils/my_popen.cpp and the (3) systemCommand function in condor_vm-gahp/vmgahp_common.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the return value of setuid calls, which might cause a subprocess to be created with… | |
| Modificada | Media (6.5) | 1.2% | — | Wisc Htcondor | 5/7/2018 | 17/6/2026 | The condor_schedd component in HTCondor before 8.6.8 and 8.7.x before 8.7.5 allows remote authenticated users to cause a denial of service (daemon crash) by leveraging use of GSI and VOMS extensions. |