CVE-2025-30093 describes an authorization bypass vulnerability affecting HTCondor versions 23.0.x, 23.10.x, 24.0.x, and 24.6.x prior to their respective patched releases. This flaw allows authenticated attackers to circumvent security restrictions, potentially leading to high impact on confidentiality and integrity. With a CVSS score of 8.1 (High), the vulnerability is network-exploitable with low attack complexity, requiring only low privileges and no user interaction. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 23.0.0, < 23.0.22CPE matchmatch criteria | cpe:2.3:a:wisc:htcondor:*:*:*:*:lts:*:*:* | ||
>= 23.10.1, < 23.10.22CPE matchmatch criteria | cpe:2.3:a:wisc:htcondor:*:*:*:*:-:*:*:* | ||
>= 24.0.1, < 24.0.6CPE matchmatch criteria | cpe:2.3:a:wisc:htcondor:*:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.