HIGH
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges
Published Jan 13, 2020
7.5
HIGHCVSS 3.1
EPSS 1.30%
Description
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00038.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1159692 x_refsource_MISCIssue TrackingThird Party Advisory
- https://lists.schedmd.com/pipermail/slurm-announce/ x_refsource_MISCMailing ListVendor Advisory
- https://www.debian.org/security/2021/dsa-4841 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.schedmd.com/news.php x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00038.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://bugzilla.suse.com/show_bug.cgi?id=1159692 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://lists.schedmd.com/pipermail/slurm-announce/ | x_refsource_MISCMailing ListVendor Advisory | |
| https://www.debian.org/security/2021/dsa-4841 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.schedmd.com/news.php | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 13, 2020
Updated Aug 5, 2024
Reserved Dec 11, 2019
Link CVE-2019-19728
CISA Vulnrichment
Updated n/a