SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade slurm_22_05-pluginsUpgrade perl-slurm_22_05Upgrade pdsh-netgroupUpgrade slurm_22_05-testsuiteUpgrade slurm_22_05-sjstatUpgrade slurm_22_05-mungeUpgrade pdsh-slurmUpgrade pdsh-gendersUpgrade pdsh-slurm_20_02Upgrade slurm_22_05-restUpgrade libnss_slurm2_22_05Upgrade pdsh-machinesUpgrade pdshUpgrade slurm_22_05-docUpgrade slurm_22_05-slurmdbdUpgrade slurm_22_05-seffUpgrade slurm_22_05-openlavaUpgrade slurm_22_05-sqlUpgrade slurm_22_05-config-manUpgrade slurm_22_05-configUpgrade pdsh-dshgroupUpgrade slurm_22_05-auth-noneUpgrade pdsh-slurm_22_05Upgrade libpmi0_22_05Upgrade slurm_22_05-torqueUpgrade pdsh-slurm_18_08Upgrade slurm_22_05-nodeUpgrade slurm_22_05-hdf5Upgrade slurm_22_05Upgrade slurm_22_05-sviewUpgrade slurm_22_05-develUpgrade libslurm38Upgrade slurm_22_05-crayUpgrade slurm_22_05-pam_slurmUpgrade slurm_22_05-webdocUpgrade pdsh-slurm_20_11Upgrade slurm_22_05-lua | Dec 1, 2022 | Nov 17, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub