cbcvebase.
CVE-2018-10995
published 2018-05-30

CVE-2018-10995: SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).

PriorityP427medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
1.74%
75.2th percentile
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
schedmdslurm<= 17.02.10.1
schedmdslurm
schedmdslurm
schedmdslurm
schedmdslurm
schedmdslurm
schedmdslurm
schedmdslurm
schedmdslurm
schedmdslurm
schedmdslurm

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.