CVE-2022-29500
published 2022-05-05CVE-2022-29500: SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.10%
79.6th percentile
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | slurm-wlm | < slurm-wlm 21.08.8.2-1 (bookworm) | slurm-wlm 21.08.8.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| schedmd | slurm | < 20.11.9 | 20.11.9 |
| schedmd | slurm | >= 21.08.0 < 21.08.08 | 21.08.08 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
slurm-llnl, slurm-wlm vulnerabilities
osv·2023-10-30·CVSS 8.8
CVE-2022-29500 [HIGH] slurm-llnl, slurm-wlm vulnerabilities
slurm-llnl, slurm-wlm vulnerabilities
It was discovered that Slurm did not properly handle credential
management, which could allow an unprivileged user to impersonate the
SlurmUser account. An attacker could possibly use this issue to execute
arbitrary code as the root user. (CVE-2022-29500)
It was discovered that Slurm did not properly handle access control when
dealing with RPC traffic through PMI2 and PMIx, which could allow an
unprivileged user to send data to an arbitrary unix socket in the host.
An attacker could possibly use this issue to execute arbitrary code as
the root user. (CVE-2022-29501)
It was discovered that Slurm did not properly handle validation logic when
processing input and output data with the srun client, which could lead to
the interception of process I/O. An
GHSA
GHSA-8g6p-72jw-r627: SchedMD Slurm 21
ghsa_unreviewed·2022-05-06
CVE-2022-29500 [HIGH] CWE-287 GHSA-8g6p-72jw-r627: SchedMD Slurm 21
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
OSV
CVE-2022-29500: SchedMD Slurm 21
osv·2022-05-05·CVSS 8.8
CVE-2022-29500 [HIGH] CVE-2022-29500: SchedMD Slurm 21
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
Ubuntu
Slurm vulnerabilities
vendor_ubuntu·2023-10-30·CVSS 8.8
CVE-2022-29501 [HIGH] Slurm vulnerabilities
Title: Slurm vulnerabilities
Summary: Several security issues were fixed in Slurm.
It was discovered that Slurm did not properly handle credential
management, which could allow an unprivileged user to impersonate the
SlurmUser account. An attacker could possibly use this issue to execute
arbitrary code as the root user. (CVE-2022-29500)
It was discovered that Slurm did not properly handle access control when
dealing with RPC traffic through PMI2 and PMIx, which could allow an
unprivileged user to send data to an arbitrary unix socket in the host.
An attacker could possibly use this issue to execute arbitrary code as
the root user. (CVE-2022-29501)
It was discovered that Slurm did not properly handle validation logic when
processing input and output data with the srun client, which coul
Debian
CVE-2022-29500: slurm-wlm - SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to...
vendor_debian·2022·CVSS 8.8
CVE-2022-29500 [HIGH] CVE-2022-29500: slurm-wlm - SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to...
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
Scope: local
bookworm: resolved (fixed in 21.08.8.2-1)
bullseye: resolved (fixed in 20.11.7+really20.11.4-2+deb11u1)
forky: resolved (fixed in 21.08.8.2-1)
sid: resolved (fixed in 21.08.8.2-1)
trixie: resolved (fixed in 21.08.8.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXLOI3ERTKMZR2KWNRN7OR5S55VPWENH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y6B7OWVNVCJUDE6VDWGCBUWMRCRETAO3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YBI4NFDGGMBKWG4EMSZL5UHATDCLPCQW/https://lists.schedmd.com/pipermail/slurm-announce/https://www.debian.org/security/2022/dsa-5166https://www.schedmd.com/news.phphttps://www.schedmd.com/news.php?id=260https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXLOI3ERTKMZR2KWNRN7OR5S55VPWENH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y6B7OWVNVCJUDE6VDWGCBUWMRCRETAO3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YBI4NFDGGMBKWG4EMSZL5UHATDCLPCQW/https://lists.schedmd.com/pipermail/slurm-announce/https://www.debian.org/security/2022/dsa-5166https://www.schedmd.com/news.phphttps://www.schedmd.com/news.php?id=260
2022-05-05
Published