Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-48936

Опубликовано: 28 окт. 2024
Источник: debian
EPSS Низкий

Описание

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
slurm-wlmfixed24.05.4-1package
slurm-wlmnot-affectedbookwormpackage
slurm-wlmnot-affectedbullseyepackage

Примечания

  • https://www.schedmd.com/slurm-version-24-05-4-is-now-available/

  • Isolated Job Step management introduced in 24.05.

EPSS

Процентиль: 25%
0.00085
Низкий

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

CVSS3: 5
nvd
больше 1 года назад

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

CVSS3: 5
github
больше 1 года назад

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

suse-cvrf
12 месяцев назад

Feature update for slurm and pdsh

suse-cvrf
12 месяцев назад

Feature update for slurm and pdsh

EPSS

Процентиль: 25%
0.00085
Низкий