GPU VulnDB

Database/Control plane, storage & DevOps

HTCondor (IDToken authorization restrictions): The per-token authorization restrictions attached with

CVE-2025-30093Control plane, storage & DevOpsHTCONDOR-2025-0001curated

Impact

The per-token authorization restrictions attached with condor_token_create -authz are not enforced. A token you deliberately minted as read-only, or scoped to one operation, performs everything the underlying identity is entitled to. Sites that use restricted tokens to hand limited access to a partner or a CI system have a boundary that does not exist.

Who can reach it

Any holder of an IDToken that the target daemon can validate. The attacker does not need to be permitted by the daemon's configured authorization policy for the restriction bypass itself.

What to do

Upgrade to HTCondor 23.0.22, 23.10.22, 24.0.6 or 24.6.1 and restart the daemons. Then inventory every token issued with -authz, or approved via condor_token_request_approve, and reissue them - each one has been operating as an unrestricted token for its identity.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.