CVE-2017-15566

EUVD-2017-7018
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 50%
Affected Products (NVD)
VendorProductVersion
schedmdslurm
𝑥
< 16.05.11
schedmdslurm
17.02.0 ≤
𝑥
< 17.2.09
schedmdslurm
17.11.0:rc1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
slurm-llnl
artful
ignored
bionic
not-affected
cosmic
not-affected
disco
not-affected
eoan
dne
focal
not-affected
groovy
not-affected
hirsute
dne
impish
dne
jammy
dne
trusty
not-affected
xenial
Fixed 15.08.7-1ubuntu0.1~esm3
released
zesty
ignored