CVE Vulnerabilities

CVE-2004-0318

Published: Nov 23, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Load Sharing Facility (LSF) 4.x, 5.x, and 6.x uses the LSF_EAUTH_UID environment variable, if it exists, instead of the real UID of the user, which could allow remote attackers within the local cluster to gain privileges.

Affected Software

NameVendorStart VersionEnd Version
LsfPlatform4.0 (including)4.0 (including)
LsfPlatform4.2 (including)4.2 (including)
LsfPlatform5.0 (including)5.0 (including)
LsfPlatform5.1 (including)5.1 (including)
LsfPlatform6.0 (including)6.0 (including)

References