CVEs (24)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running...Show more |
An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthori...Show more |
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The fixed versions are 22.05.11, 23.02.7, and...Show more |
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of service. The fixed versions are 22.05.11, 23.02.7, and 23.11.1. |
An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. An attacker can reuse root-level authentication tokens during interaction with...Show more |
An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1. |
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integrity During Transmission in a Communication Channel. This allows attackers to modify RPC traffic in a...Show more |
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files. |
2Fedoraproject Schedmd2Fedora SlurmNov 21, 2024 May 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. |
3Debian FedoraprojectSchedmd3Debian Linux FedoraSlurmNov 21, 2024 May 5, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution. |
3Debian FedoraprojectSchedmd3Debian Linux FedoraSlurmNov 21, 2024 May 5, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure. |
2Fedoraproject Schedmd2Fedora SlurmNov 21, 2024 Nov 17, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scrip...Show more |
3Debian FedoraprojectSchedmd3Debian Linux FedoraSlurmNov 21, 2024 May 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling. |
2Debian Schedmd2Debian Linux SlurmNov 21, 2024 Nov 27, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem. |
2Debian Schedmd2Debian Linux SlurmNov 21, 2024 Nov 27, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreNov 21, 2024 May 21, 2020 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a pr...Show more |
3Debian OpensuseSchedmd3Debian Linux LeapSlurmNov 21, 2024 Jan 13, 2020 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges. |
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreNov 21, 2024 Jul 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. |
SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems. |