Condor Project develops a distributed high-throughput computing system widely deployed in academic and research computing environments, where its job-scheduling and resource-management role places it at a critical point in many computational workflows. The vulnerability profile centers on the Condor platform itself and recurs through weakness classes including improper input validation, authentication flaws, memory-safety issues, and exposure of sensitive information—challenges typical of a long-lived distributed system handling scheduling, credential management, and inter-process communication. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Condor Project over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3416HIGH Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by connecting from a system with a sp | Aug 25, 2012 | 10.0 | 33 | NO | NO |
CVE-2012-5390HIGH The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attac | Jun 6, 2014 | 10.0 | 30 | NO | NO |
CVE-2012-5197HIGH Multiple unspecified vulnerabilities in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors related to "error checking of system calls." | Sep 28, 2012 | 10.0 | 28 | NO | NO |
CVE-2012-5196HIGH Multiple buffer overflows in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 have unknown impact and attack vectors. | Sep 28, 2012 | 10.0 | 28 | NO | NO |
CVE-2012-3492MEDIUM The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories even when they have weak permissio | Sep 28, 2012 | 6.4 | 21 | NO | NO |
CVE-2012-3493MEDIUM The command_give_request_ad function in condor_startd.V6/command.cpp Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 allows remote attackers to obtain sensitive information, and | Sep 28, 2012 | 5.8 | 20 | NO | NO |
CVE-2008-3424HIGH Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, whi | Jul 31, 2008 | 7.5 | 20 | NO | NO |
CVE-2009-4133MEDIUM Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and | Dec 23, 2009 | 6.5 | 18 | NO | NO |
CVE-2008-3830HIGH Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers | Oct 8, 2008 | 7.2 | 18 | NO | NO |
CVE-2011-4930MEDIUM Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local user | Feb 10, 2014 | 4.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Condor Project.
Media articles that mention a CVE ID that affects a product developed by Condor Project — matched by CVE ID, not by vendor name.