PT-2023-8176 · Schedmd+4 · Slurm+4
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SchedMD Slurm versions 22.05.x through 22.05.10
SchedMD Slurm versions 23.02.x through 23.02.6
Description
The issue is related to the sbcast subsystem of the Slurm resource management system and is associated with weaknesses in the authentication procedure. This can allow a remote attacker to bypass existing security restrictions. The problem is due to incorrect access control, which enables an attacker to modify their extended group list used with the sbcast subsystem and open files with an unauthorized set of extended groups.
Recommendations
For SchedMD Slurm versions 22.05.x through 22.05.10, update to version 22.05.11 to resolve the issue.
For SchedMD Slurm versions 23.02.x through 23.02.6, update to version 23.02.7 to resolve the issue.
As a temporary workaround, consider restricting access to the sbcast subsystem until a patch is applied.
Exploit
Fix
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Slurm
Suse
Ubuntu