CVE-2025-66433: Medium severity HTCondor Access Point vulnerability
HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by submitting a batch job. This is fixed in 24.12.14, 25.0.3, and 25.3.1. The earliest affected version is 24.7.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66433?
CVE-2025-66433 is classified as a medium severity vulnerability due to its potential to allow authenticated users to impersonate others.
How do I fix CVE-2025-66433?
To fix CVE-2025-66433, upgrade to HTCondor Access Point versions 24.12.14, 25.0.3, or 25.3.1.
Who is affected by CVE-2025-66433?
All users of HTCondor Access Point versions between 24.7.3 and 25.3.0 are affected by CVE-2025-66433.
What does CVE-2025-66433 exploit?
CVE-2025-66433 allows authenticated users to impersonate other users by submitting a batch job.
What versions of HTCondor Access Point should I avoid due to CVE-2025-66433?
Avoid using HTCondor Access Point versions from 24.7.3 up to and including 25.3.0 to mitigate the risk from CVE-2025-66433.