Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-31215

Опубликовано: 13 мая 2021
Источник: debian
EPSS Низкий

Описание

SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
slurm-wlmfixed20.11.7+really20.11.4-2package
slurm-llnlremovedpackage
slurm-llnlno-dsabusterpackage

Примечания

  • https://github.com/SchedMD/slurm/commit/a9e9e2fedbd200ca545ab67dd753bd52c919f236 (2.11.7)

  • Initially already fixed in 20.11.7-1 (the tracker would do the right thing)

  • but the unstable upload invalidated the changelog 20.11.7-1 so use 20.11.7+really20.11.4-2

  • for consistency with BTS.

EPSS

Процентиль: 85%
0.02536
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling.

CVSS3: 8.8
nvd
больше 4 лет назад

SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling.

suse-cvrf
больше 4 лет назад

Security update for slurm

suse-cvrf
больше 4 лет назад

Security update for slurm

suse-cvrf
больше 4 лет назад

Security update for slurm_20_11

EPSS

Процентиль: 85%
0.02536
Низкий