Home/Product/schedmd slurm
Product

schedmd slurm

27 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-48936
< 24.05.4
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker
5.0MEDIUM
CVE-2023-49938
>= 22.05.0 and < 22.05.11
An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their ex
8.2HIGH
CVE-2023-49937
>= 22.05 and < 22.05.12
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of
9.8CRITICAL
CVE-2023-49936
>= 22.05 and < 22.05.12
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of service. The
7.5HIGH
CVE-2023-49935
>= 23.02 and < 23.02.7
An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integr
8.8HIGH
CVE-2023-49934
all versions
An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11
9.8CRITICAL
CVE-2023-49933
>= 22.05 and < 22.05.12
An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integrity During
7.5HIGH
CVE-2023-41914
>= 22.05 and < 22.05.10
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file
7.0HIGH
CVE-2022-29502
>= 21.08.0 and < 21.08.08
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
9.8CRITICAL
CVE-2022-29501
< 20.11.9
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.
8.8HIGH
CVE-2022-29500
< 20.11.9
SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
8.8HIGH
CVE-2021-43337
>= 21.08.0 and < 21.08.4
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or j
6.5MEDIUM
CVE-2021-31215
< 20.02.7
SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a
8.8HIGH
CVE-2020-27746
< 19.05.8
Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic co
3.7LOW
CVE-2020-27745
< 19.05.8
Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
9.8CRITICAL
CVE-2020-12693
>= 19.05.0 and < 19.05.7
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authenticat
8.1HIGH
CVE-2019-19728
< 18.08.9
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
7.5HIGH
CVE-2019-19727
< 18.08.9
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
5.5MEDIUM
CVE-2019-12838
> 17.11.0.0 and <= 17.11.13.2
SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
9.8CRITICAL
CVE-2019-6438
< 17.11.13
SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.
9.8CRITICAL
CVE-2018-10995
<= 17.02.10.1
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid field
5.3MEDIUM
CVE-2018-7033
< 17.02.10.0
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
9.8CRITICAL
CVE-2017-15566
< 16.05.11
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.1
7.8HIGH
CVE-2016-10030
<= 15.08.12
The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 has a vulne
8.1HIGH
CVE-2010-3380
<= 2.1.13
The (1) init.d/slurm and (2) init.d/slurmdbd scripts in SLURM before 2.1.14 place the . (dot) directory in the LD_LIBRARY_PATH, wh
CVE-2009-2084
<= 1.3.13
Simple Linux Utility for Resource Management (SLURM) 1.2 and 1.3 before 1.3.14 does not properly set supplementary groups before i
CVE-2009-0128
all versions
plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properl
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin