CVE Vulnerabilities

CVE-2019-19728

Improper Privilege Management

Published: Jan 13, 2020 | Modified: Jan 28, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun –uid with incorrect privileges.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Slurm Schedmd * 18.08.9 (excluding)
Slurm Schedmd 19.05.0 (including) 19.05.5 (excluding)

Potential Mitigations

References