CVE-2022-29502
published 2022-05-05CVE-2022-29502: SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.68%
74.3th percentile
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | slurm-wlm | < slurm-wlm 21.08.8.2-1 (bookworm) | slurm-wlm 21.08.8.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| schedmd | slurm | >= 21.08.0 < 21.08.08 | 21.08.08 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Slurm vulnerabilities
vendor_ubuntu·2023-10-30·CVSS 8.8
CVE-2022-29501 [HIGH] Slurm vulnerabilities
Title: Slurm vulnerabilities
Summary: Several security issues were fixed in Slurm.
It was discovered that Slurm did not properly handle credential
management, which could allow an unprivileged user to impersonate the
SlurmUser account. An attacker could possibly use this issue to execute
arbitrary code as the root user. (CVE-2022-29500)
It was discovered that Slurm did not properly handle access control when
dealing with RPC traffic through PMI2 and PMIx, which could allow an
unprivileged user to send data to an arbitrary unix socket in the host.
An attacker could possibly use this issue to execute arbitrary code as
the root user. (CVE-2022-29501)
It was discovered that Slurm did not properly handle validation logic when
processing input and output data with the srun client, which coul
Debian
CVE-2022-29502: slurm-wlm - SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to...
vendor_debian·2022·CVSS 9.8
CVE-2022-29502 [CRITICAL] CVE-2022-29502: slurm-wlm - SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to...
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
Scope: local
bookworm: resolved (fixed in 21.08.8.2-1)
bullseye: resolved
forky: resolved (fixed in 21.08.8.2-1)
sid: resolved (fixed in 21.08.8.2-1)
trixie: resolved (fixed in 21.08.8.2-1)
OSV
slurm-llnl, slurm-wlm vulnerabilities
osv·2023-10-30·CVSS 8.8
CVE-2022-29500 [HIGH] slurm-llnl, slurm-wlm vulnerabilities
slurm-llnl, slurm-wlm vulnerabilities
It was discovered that Slurm did not properly handle credential
management, which could allow an unprivileged user to impersonate the
SlurmUser account. An attacker could possibly use this issue to execute
arbitrary code as the root user. (CVE-2022-29500)
It was discovered that Slurm did not properly handle access control when
dealing with RPC traffic through PMI2 and PMIx, which could allow an
unprivileged user to send data to an arbitrary unix socket in the host.
An attacker could possibly use this issue to execute arbitrary code as
the root user. (CVE-2022-29501)
It was discovered that Slurm did not properly handle validation logic when
processing input and output data with the srun client, which could lead to
the interception of process I/O. An
GHSA
GHSA-56x4-r7hf-449r: SchedMD Slurm 21
ghsa_unreviewed·2022-05-06
CVE-2022-29502 [CRITICAL] GHSA-56x4-r7hf-449r: SchedMD Slurm 21
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
OSV
CVE-2022-29502: SchedMD Slurm 21
osv·2022-05-05·CVSS 9.8
CVE-2022-29502 [CRITICAL] CVE-2022-29502: SchedMD Slurm 21
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXLOI3ERTKMZR2KWNRN7OR5S55VPWENH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y6B7OWVNVCJUDE6VDWGCBUWMRCRETAO3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YBI4NFDGGMBKWG4EMSZL5UHATDCLPCQW/https://lists.schedmd.com/pipermail/slurm-announce/https://www.schedmd.com/news.phphttps://www.schedmd.com/news.php?id=260https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXLOI3ERTKMZR2KWNRN7OR5S55VPWENH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y6B7OWVNVCJUDE6VDWGCBUWMRCRETAO3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YBI4NFDGGMBKWG4EMSZL5UHATDCLPCQW/https://lists.schedmd.com/pipermail/slurm-announce/https://www.schedmd.com/news.phphttps://www.schedmd.com/news.php?id=260
2022-05-05
Published