PT-2019-10300 · Univa · Univa Grid Engine
Published
2019-07-30
·
Updated
2020-08-24
·
CVE-2018-20871
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Univa Grid Engine versions prior to 8.6.3
Description:
The issue arises when Univa Grid Engine is configured for Docker jobs and execd spooling on root squash, leading to weak file permissions with "other" write access in certain cases.
Recommendations:
For versions prior to 8.6.3, update to version 8.6.3 or later to resolve the issue.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Univa Grid Engine