CVE-2012-3491

src/condor_schedd.V6/schedd.cpp in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 does not properly check the permissions of jobs, which allows remote authenticated users to remove arbitrary idle jobs via unspecified vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:condor_project:condor:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.3:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.4:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.5:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.6:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.7:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.8:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.6.9:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.8.0:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.8.1:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.8.2:*:*:*:*:*:*:*
cpe:2.3:a:condor_project:condor:7.8.3:*:*:*:*:*:*:*

History

07 Nov 2023, 02:11

Type Values Removed Values Added
References
  • {'url': 'http://condor-git.cs.wisc.edu/?p=condor.git;a=commitdiff;h=1fff5d40', 'name': 'http://condor-git.cs.wisc.edu/?p=condor.git;a=commitdiff;h=1fff5d40', 'tags': ['Exploit'], 'refsource': 'CONFIRM'}
  • () http://condor-git.cs.wisc.edu/?p=condor.git%3Ba=commitdiff%3Bh=1fff5d40 -

Information

Published : 2012-09-28 17:55

Updated : 2023-12-10 11:16


NVD link : CVE-2012-3491

Mitre link : CVE-2012-3491

CVE.ORG link : CVE-2012-3491


JSON object : View

Products Affected

condor_project

  • condor
CWE
CWE-264

Permissions, Privileges, and Access Controls