PT-2020-5854 · Schedmd+3 · Slurm+3
Published
2020-10-27
·
Updated
2024-06-15
·
CVE-2020-27746
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Slurm versions 19.05.7 and earlier, 20.x before 20.02.6
Description:
The issue is related to the exposure of sensitive information due to a race condition in a read operation on the /proc filesystem, affecting xauth for X11 magic cookies. This allows an unauthorized actor to access confidential data. The vulnerability is associated with the insecure storage of confidential information.
Recommendations:
For Slurm versions 19.05.7 and earlier, update to version 19.05.8 or later.
For Slurm versions 20.x before 20.02.6, update to version 20.02.6 or later.
As a temporary workaround, consider restricting access to the xauth for X11 magic cookies to minimize the risk of exploitation.
Fix
Race Condition
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Slurm
Suse
Ubuntu