CVE-2013-4495: Adaptivecomputing Torque Resource Manager

High severity, CVSS 10.0. EPSS: 3.3% chance of exploitation in the next 30 days.

The send_the_mail function in server/svr_mail.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 4.2.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the email (-M switch) to qsub.

Affected products

  • Adaptivecomputing Torque Resource Manager: up to and including 4.2.5; version 2.0.0 only; version 2.1.2 only; version 2.1.3 only; version 2.1.6 only; version 2.1.7 only; …

Published 2013-11-20. Last modified 2026-06-16.