- EPSS 0.11%
- Veröffentlicht 28.10.2024 04:15:02
- Zuletzt bearbeitet 17.04.2025 18:52:54
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems ...
CVE-2023-49938
- EPSS 0.15%
- Veröffentlicht 14.12.2023 05:15:11
- Zuletzt bearbeitet 21.11.2024 08:34:02
An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. Th...
CVE-2023-49937
- EPSS 0.26%
- Veröffentlicht 14.12.2023 05:15:11
- Zuletzt bearbeitet 21.11.2024 08:34:02
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.
CVE-2023-49936
- EPSS 0.17%
- Veröffentlicht 14.12.2023 05:15:10
- Zuletzt bearbeitet 21.11.2024 08:34:02
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of service. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.
CVE-2023-49935
- EPSS 0.04%
- Veröffentlicht 14.12.2023 05:15:10
- Zuletzt bearbeitet 21.11.2024 08:34:02
An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. An attacker can reuse root-level authentication tokens during interaction with the slurmd process. This bypa...
CVE-2023-49934
- EPSS 0.14%
- Veröffentlicht 14.12.2023 05:15:10
- Zuletzt bearbeitet 21.11.2024 08:34:02
An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1.
CVE-2023-49933
- EPSS 0.04%
- Veröffentlicht 14.12.2023 05:15:08
- Zuletzt bearbeitet 21.11.2024 08:34:02
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integrity During Transmission in a Communication Channel. This allows attackers to modify RPC traffic in a way that bypasses message hash...
- EPSS 0.06%
- Veröffentlicht 03.11.2023 05:15:30
- Zuletzt bearbeitet 21.11.2024 08:21:54
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.
CVE-2022-29502
- EPSS 0.6%
- Veröffentlicht 05.05.2022 17:15:15
- Zuletzt bearbeitet 21.11.2024 06:59:12
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
- EPSS 1.55%
- Veröffentlicht 05.05.2022 17:15:15
- Zuletzt bearbeitet 21.11.2024 06:59:12
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.