Описание
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 17.11.2-1build1 |
| cosmic | not-affected | 17.11.2-1build1 |
| devel | DNE | |
| disco | not-affected | 17.11.2-1build1 |
| eoan | DNE | |
| esm-apps/bionic | not-affected | 17.11.2-1build1 |
| esm-apps/focal | not-affected | 19.05.3.2-2 |
| esm-apps/xenial | released | 15.08.7-1ubuntu0.1~esm3 |
| esm-infra-legacy/trusty | not-affected | code not present |
Показывать по
7.2 High
CVSS2
7.8 High
CVSS3
Связанные уязвимости
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
Insecure SPANK environment variable handling exists in SchedMD Slurm b ...
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
Уязвимость менеджера управления ресурсами Slurm, связанная с некорректной обработкой переменной окружения SPANK, позволяющая нарушителю повысить свои привилегии
7.2 High
CVSS2
7.8 High
CVSS3