CVE-2025-30093
published 2025-03-27CVE-2025-30093: HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization…
PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.33%
25.3th percentile
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| condor_project | condor | >= 0 < 23.9.6+dfsg-2 | 23.9.6+dfsg-2 |
| condor_project | condor | >= 0 < 23.9.6+dfsg-2 | 23.9.6+dfsg-2 |
| debian | condor | < condor 23.9.6+dfsg-2 (forky) | condor 23.9.6+dfsg-2 (forky) |
| wisc | htcondor | >= 23.0.0 < 23.0.22 | 23.0.22 |
| wisc | htcondor | >= 23.10.1 < 23.10.22 | 23.10.22 |
| wisc | htcondor | >= 24.0.1 < 24.0.6 | 24.0.6 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-30093: HTCondor 23
osv·2025-03-27·CVSS 8.1
CVE-2025-30093 [HIGH] CVE-2025-30093: HTCondor 23
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.
GHSA
GHSA-v64g-gxm8-whwj: HTCondor 23
ghsa_unreviewed·2025-03-27
CVE-2025-30093 [HIGH] CWE-863 GHSA-v64g-gxm8-whwj: HTCondor 23
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.
Debian
CVE-2025-30093: condor - HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, a...
vendor_debian·2025·CVSS 8.1
CVE-2025-30093 [HIGH] CVE-2025-30093: condor - HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, a...
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.
Scope: local
forky: resolved (fixed in 23.9.6+dfsg-2)
sid: resolved (fixed in 23.9.6+dfsg-2)
trixie: resolved (fixed in 23.9.6+dfsg-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-27
Published