PT-2025-20326 · Slurm+2 · Slurm+2

Published

2025-01-01

·

Updated

2026-05-06

·

CVE-2025-43904

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Slurm versions 22.05, 23.02, 23.11.11, 24.05.8, and 24.11.5 are affected.
Description The issue is related to permission handling for Coordinators within the accounting system, allowing them to promote a user to Administrator. This is due to an issue with permission handling, which can be exploited by Coordinators. The vulnerability affects various versions of Slurm, including 22.05, 23.02, 23.11.11, 24.05.8, and 24.11.5.
Recommendations Update to version 24.11.5 or later to fix the security issue. For versions prior to 24.11.5, update to the latest available version to mitigate the risk. As a temporary workaround, consider restricting the privileges of Coordinators within the accounting system until a patch is available. Restrict access to the vulnerable slurmrestd API endpoints, such as GET /slurm/v0.0.40/jobs/state/, GET /slurm/v0.0.41/jobs/state/, and GET /slurm/v0.0.42/jobs/state/, to minimize the risk of exploitation.

Exploit

Fix

LPE

Incorrect Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09836
CVE-2025-43904
DSA-5961-1
MGASA-2025-0215
OPENSUSE-SU-2025:15165-1
OPENSUSE-SU-2025_01756-1
OPENSUSE-SU-2025_01758-1
OPENSUSE-SU-2025_01759-1
OPENSUSE-SU-2025_01760-1
OPENSUSE-SU-2025_01761-1
SUSE-SU-2025:01751-1
SUSE-SU-2025:01752-1
SUSE-SU-2025:01753-1
SUSE-SU-2025:01755-1
SUSE-SU-2025:01756-1
SUSE-SU-2025:01757-1
SUSE-SU-2025:01758-1
SUSE-SU-2025:01759-1
SUSE-SU-2025:01760-1
SUSE-SU-2025:01761-1
SUSE-SU-2025:02779-1
SUSE-SU-2025_01751-1
SUSE-SU-2025_01752-1
SUSE-SU-2025_01753-1
SUSE-SU-2025_01755-1
SUSE-SU-2025_01757-1
SUSE-SU-2025_01758-1
SUSE-SU-2025_01759-1
SUSE-SU-2025_01761-1
USN-8236-1

Affected Products

Debian
Slurm
Ubuntu