9.8

CVE-2019-12838

SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schedmd ≫ Slurm Version > 17.11.0.0 <= 17.11.13.2
Schedmd ≫ Slurm Version > 18.08.0 <= 18.08.7
Schedmd ≫ Slurm Version 19.05.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 29
Fedoraproject ≫ Fedora Version 30
Opensuse ≫ Leap Version 15.0
Opensuse ≫ Leap Version 15.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.68% 0.839
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://lists.debian.org/debian-lts-announce/2020/03/msg00016.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00005.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00051.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00038.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2022/01/msg00011.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2O47F72FWMYLEGF35QGNYY5VS33SUQS5/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQ6EV3OWKGMTBWCSXZGS4MYADUBLVXSQ/
https://lists.schedmd.com/pipermail/slurm-announce/2019/
Vendor Advisory
Release Notes
https://lists.schedmd.com/pipermail/slurm-announce/2019/000025.html
Vendor Advisory
Mailing List
https://seclists.org/bugtraq/2019/Nov/30
Third Party Advisory
Mailing List
https://www.debian.org/security/2019/dsa-4572
Third Party Advisory
https://www.schedmd.com/news.php
Vendor Advisory
https://www.schedmd.com/news.php?id=218
Vendor Advisory
Release Notes