PT-2020-5854 · Schedmd+3 · Slurm+3

Published

2020-10-27

·

Updated

2024-06-15

·

CVE-2020-27746

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Slurm versions 19.05.7 and earlier, 20.x before 20.02.6
Description: The issue is related to the exposure of sensitive information due to a race condition in a read operation on the /proc filesystem, affecting xauth for X11 magic cookies. This allows an unauthorized actor to access confidential data. The vulnerability is associated with the insecure storage of confidential information.
Recommendations: For Slurm versions 19.05.7 and earlier, update to version 19.05.8 or later. For Slurm versions 20.x before 20.02.6, update to version 20.02.6 or later. As a temporary workaround, consider restricting access to the xauth for X11 magic cookies to minimize the risk of exploitation.

Fix

Race Condition

Insecure Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01898
CVE-2020-27746
DSA-4841-1
OPENSUSE-SU-2020:2033-1
OPENSUSE-SU-2020:2056-1
OPENSUSE-SU-2020:2286-1
OPENSUSE-SU-2020_2033-1
OPENSUSE-SU-2020_2056-1
OPENSUSE-SU-2020_2286-1
OPENSUSE-SU-2021:0096-1
OPENSUSE-SU-2021_0096-1
OPENSUSE-SU-2024:11389-1
SUSE-SU-2020:3505-1
SUSE-SU-2020:3506-1
SUSE-SU-2020:3863-1
SUSE-SU-2020:3877-1
SUSE-SU-2020:3878-1
SUSE-SU-2020:3892-1
SUSE-SU-2021:0139-1
SUSE-SU-2021:0773-1
USN-4781-1

Affected Products

Linuxmint
Slurm
Suse
Ubuntu