PT-2021-23816 · Schedmd · Schedmd Slurm
Published
2021-11-17
·
Updated
2022-12-08
·
CVE-2021-43337
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SchedMD Slurm versions 21.08.* through 21.08.3
Description
The issue concerns incorrect access control in SchedMD Slurm. Specifically, on sites using the new AccountingStoreFlags options for job scripts and/or job environment, the access control rules in SlurmDBD may allow users to access job scripts and environment files that they should not have access to.
Recommendations
For SchedMD Slurm versions 21.08.* through 21.08.3, update to version 21.08.4 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Schedmd Slurm