CVE-2023-49938 โ€” Slurm vulnerability

5 documents5 sources
Severity
8.2HIGHNVD
EPSS
0.3%
top 44.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 14

Description

An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NExploitability: 3.9 | Impact: 4.2

Affected Packages1 packages

โ–ถNVDschedmd/slurm22.05.0 โ€” 22.05.11+1

๐Ÿ”ดVulnerability Details

3
CVEList
CVE-2023-49938: An issue was discovered in SchedMD Slurm 22โ†—2023-12-14
โ–ถ
GHSA
GHSA-3j4p-qc5m-wqgh: An issue was discovered in SchedMD Slurm 22โ†—2023-12-14
โ–ถ
OSV
CVE-2023-49938: An issue was discovered in SchedMD Slurm 22โ†—2023-12-14
โ–ถ

๐Ÿ“‹Vendor Advisories

1
Debian
CVE-2023-49938: slurm-wlm - An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect...โ†—2023
โ–ถ
CVE-2023-49938 โ€” Schedmd Slurm vulnerability | cvebase