CVE-2021-43337
published 2021-11-17CVE-2021-43337: SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.20%
64.7th percentile
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | slurm-wlm | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| schedmd | slurm | >= 21.08.0 < 21.08.4 | 21.08.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-43337: slurm-wlm - SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites usin...
vendor_debian·2021·CVSS 6.5
CVE-2021-43337 [MEDIUM] CVE-2021-43337: slurm-wlm - SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites usin...
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-c6cp-7frc-r847: SchedMD Slurm 21
ghsa_unreviewed·2022-05-24
CVE-2021-43337 [MEDIUM] CWE-863 GHSA-c6cp-7frc-r847: SchedMD Slurm 21
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.
OSV
CVE-2021-43337: SchedMD Slurm 21
osv·2021-11-17·CVSS 6.5
CVE-2021-43337 [MEDIUM] CVE-2021-43337: SchedMD Slurm 21
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VY34WSSPRPA6MISNYBZWHSGX2SYSEEE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DUWNGDQTS7AWFI7FIHUWQOYJSD2IQTCG/https://lists.schedmd.com/pipermail/slurm-announce/https://lists.schedmd.com/pipermail/slurm-announce/2021/000068.htmlhttps://www.schedmd.com/news.phphttps://www.schedmd.com/news.php?id=256https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VY34WSSPRPA6MISNYBZWHSGX2SYSEEE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DUWNGDQTS7AWFI7FIHUWQOYJSD2IQTCG/https://lists.schedmd.com/pipermail/slurm-announce/https://lists.schedmd.com/pipermail/slurm-announce/2021/000068.htmlhttps://www.schedmd.com/news.phphttps://www.schedmd.com/news.php?id=256
2021-11-17
Published