Schedmd
Schedmd Slurm: vulnerabilidades y CVE
Schedmd Slurm tiene 25 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE25
Últimos 12 meses1
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-43904 | Media (4.2) | 0.26% | — | 16 ene 2026 | In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator. |
| CVE-2024-48936 | Media (5) | 0.35% | — | 28 oct 2024 | SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running… |
| CVE-2023-49938 | Alta (8.2) | 0.76% | — | 14 dic 2023 | An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an… |
| CVE-2023-49937 | Crítica (9.8) | 1.4% | — | 14 dic 2023 | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The fixed versions are 22.05.11, 23.02.7, and… |
| CVE-2023-49936 | Alta (7.5) | 1.1% | — | 14 dic 2023 | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. A NULL pointer dereference leads to denial of service. The fixed versions are 22.05.11, 23.02.7, and 23.11.1. |
| CVE-2023-49935 | Alta (8.8) | 1.0% | — | 14 dic 2023 | An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. An attacker can reuse root-level authentication tokens during interaction… |
| CVE-2023-49934 | Crítica (9.8) | 0.77% | — | 14 dic 2023 | An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1. |
| CVE-2023-49933 | Alta (7.5) | 0.38% | — | 14 dic 2023 | An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integrity During Transmission in a Communication Channel. This allows attackers to modify RPC traffic in a… |
| CVE-2023-41914 | Alta (7) | 0.20% | — | 3 nov 2023 | SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files. |
| CVE-2022-29502 | Crítica (9.8) | 1.8% | — | 5 may 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. |
| CVE-2022-29501 | Alta (8.8) | 3.0% | — | 5 may 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution. |
| CVE-2022-29500 | Alta (8.8) | 2.3% | — | 5 may 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure. |
| CVE-2021-43337 | Media (6.5) | 1.2% | — | 17 nov 2021 | SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job… |
| CVE-2021-31215 | Alta (8.8) | 2.9% | — | 13 may 2021 | SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling. |
| CVE-2020-27746 | Baja (3.7) | 0.83% | — | 27 nov 2020 | Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem. |
| CVE-2020-27745 | Crítica (9.8) | 2.2% | — | 27 nov 2020 | Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin. |
| CVE-2020-12693 | Alta (8.1) | 2.3% | — | 21 may 2020 | Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a… |
| CVE-2019-19728 | Alta (7.5) | 1.3% | — | 13 ene 2020 | SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges. |
| CVE-2019-19727 | Media (5.5) | 0.35% | — | 13 ene 2020 | SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions. |
| CVE-2019-12838 | Crítica (9.8) | 2.7% | — | 11 jul 2019 | SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. |
| CVE-2019-6438 | Crítica (9.8) | 2.3% | — | 31 ene 2019 | SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems. |
| CVE-2018-10995 | Media (5.3) | 1.7% | — | 30 may 2018 | SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields). |
| CVE-2018-7033 | Crítica (9.8) | 2.0% | — | 15 mar 2018 | SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD. |
| CVE-2017-15566 | Alta (7.8) | 0.58% | — | 1 nov 2017 | Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution. |
| CVE-2016-10030 | Alta (8.1) | 2.5% | — | 5 ene 2017 | The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 has a vulnerability in how the slurmd daemon informs users of a Prolog failure on a compute node.… |