CVE Vulnerabilities

CVE-2020-12693

Published: May 21, 2020 | Modified: Nov 07, 2023
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.

Affected Software

Name Vendor Start Version End Version
Slurm Schedmd 19.05.0 (including) 19.05.7 (excluding)
Slurm Schedmd 20.02.0 (including) 20.02.3 (excluding)

References