Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8phj-c26v-2jj9

Опубликовано: 28 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

EPSS

Процентиль: 29%
0.0035
Низкий

5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5
ubuntu
почти 2 года назад

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

CVSS3: 5
nvd
почти 2 года назад

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

CVSS3: 5
debian
почти 2 года назад

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in ...

suse-cvrf
больше 1 года назад

Feature update for slurm and pdsh

suse-cvrf
больше 1 года назад

Feature update for slurm and pdsh

EPSS

Процентиль: 29%
0.0035
Низкий

5 Medium

CVSS3

Дефекты

CWE-863