A flaw was found in the way Condor interpreted wildcards in authorization
lists. Certain authorization lists using wildcards in DENY rules, such as
DENY_WRITE or HOSTDENY_WRITE, that conflict with the definitions in ALLOW
rules, could permit authenticated remote users to submit computation jobs,
even when such access should have been denied. (CVE-2008-3424)