Home
MEDIUM: 4.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
24.7.3 (custom) before 24.12.14
affected
25.0.0 (custom) before 25.0.3
affected
25.1.0 (custom) before 25.3.1
affected
Description
HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed in 24.12.14, 25.0.3, and 25.3.1. The earliest affected version is 24.7.3.
Problem types
CWE-863 Incorrect Authorization
Product status
24.7.3 (custom) before 24.12.14
25.0.0 (custom) before 25.0.3
25.1.0 (custom) before 25.3.1
References
htcondor.org/...rity/vulnerabilities/HTCONDOR-2025-0002.html