CVE-2023-49935
14.12.2023, 05:15
An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. An attacker can reuse root-level authentication tokens during interaction with the slurmd process. This bypasses the RPC message hashes that protect against undesired MUNGE credential reuse. The fixed versions are 23.02.7 and 23.11.1.Enginsight
Vendor | Product | Version |
---|---|---|
schedmd | slurm | 23.02 ≤ 𝑥 < 23.02.7 |
schedmd | slurm | 23.11 |
schedmd | slurm | 23.11:rc1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References