Schedmd Slurm vulnerabilities
25 known vulnerabilities affecting schedmd/slurm.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH12MEDIUM5LOW1
Vulnerabilities
Page 2 of 2
CVE-2024-48936P4MEDIUMCVSS 5.0fixed in 24.05.42024-10-28
CVE-2024-48936 [MEDIUM] CWE-863 CVE-2024-48936: SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in st
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
nvd
CVE-2018-10995P4MEDIUMCVSS 5.3≤ 17.02.10.1v17.11.0.0+9 more2018-05-30
CVE-2018-10995 [MEDIUM] CWE-20 CVE-2018-10995: SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).
nvd
CVE-2019-19727P4MEDIUMCVSS 5.5fixed in 18.08.9≥ 19.05.0, < 19.05.52020-01-13
CVE-2019-19727 [MEDIUM] CWE-732 CVE-2019-19727: SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
nvd
CVE-2025-43904P4MEDIUMCVSS 4.2fixed in 23.11.11≥ 24, < 24.05.8+1 more2026-01-16
CVE-2025-43904 [MEDIUM] CWE-863 CVE-2025-43904: In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinato
In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.
nvd
CVE-2020-27746P4LOWCVSS 3.7fixed in 19.05.8≥ 20.0.0, < 20.02.62020-11-27
CVE-2020-27746 [LOW] CWE-362 CVE-2020-27746: Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor
Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.
nvd
← Previous2 / 2