CVE Vulnerabilities

CVE-2019-19728

Improper Privilege Management

Published: Jan 13, 2020 | Modified: Jan 28, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun –uid with incorrect privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Slurm Schedmd * 18.08.9 (excluding)
Slurm Schedmd 19.05.0 (including) 19.05.5 (excluding)
Slurm-llnl Ubuntu bionic *
Slurm-llnl Ubuntu disco *
Slurm-llnl Ubuntu esm-apps/bionic *
Slurm-llnl Ubuntu esm-apps/xenial *
Slurm-llnl Ubuntu esm-infra-legacy/trusty *
Slurm-llnl Ubuntu trusty *
Slurm-llnl Ubuntu trusty/esm *
Slurm-llnl Ubuntu xenial *

Potential Mitigations

References