CVE-2012-3493: Condor Project Condor

Medium severity, CVSS 5.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and possibly control or start arbitrary jobs, via a ClassAd request to the condor_startd port, which leaks the ClaimId.

Affected products

  • Condor Project Condor: version 7.6.0 only; version 7.6.1 only; version 7.6.2 only; version 7.6.3 only; version 7.6.4 only; version 7.6.5 only; …

Published 2012-09-28. Last modified 2026-06-16.