CVE-2019-19727Incorrect Permission Assignment in Slurm

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 85.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 24

Description

SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDschedmd/slurm19.05.019.05.5+1
NVDopensuse/leap15.1

🔴Vulnerability Details

3
GHSA
GHSA-wmqm-x8vm-v6mh: SchedMD Slurm before 182022-05-24
CVEList
CVE-2019-19727: SchedMD Slurm before 182020-01-13
OSV
CVE-2019-19727: SchedMD Slurm before 182020-01-13
CVE-2019-19727 — Incorrect Permission Assignment | cvebase