Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2022-29500

Disclosure Date: May 05, 2022 (last updated October 07, 2023)
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
Attacker Value
Unknown

CVE-2021-43337

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.
Attacker Value
Unknown

CVE-2021-31215

Disclosure Date: May 13, 2021 (last updated November 08, 2023)
SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling.
Attacker Value
Unknown

CVE-2020-27746

Disclosure Date: November 27, 2020 (last updated February 22, 2025)
Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.
Attacker Value
Unknown

CVE-2020-27745

Disclosure Date: November 27, 2020 (last updated February 22, 2025)
Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
Attacker Value
Unknown

CVE-2020-12693

Disclosure Date: May 21, 2020 (last updated February 21, 2025)
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
Attacker Value
Unknown

CVE-2019-19727

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
Attacker Value
Unknown

CVE-2019-19728

Disclosure Date: August 08, 2019 (last updated February 21, 2025)
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
Attacker Value
Unknown

CVE-2019-12838

Disclosure Date: July 11, 2019 (last updated November 08, 2023)
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
Attacker Value
Unknown

CVE-2019-6438

Disclosure Date: January 31, 2019 (last updated November 27, 2024)
SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.
0