VDB

CVE-2020-12693

CVE-2020-12693 PUBLISHED

Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.

EPSS 0.63% · 70.8th percentile

Risk Scores

EPSS Score
0.63%
70.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSslurm-llnl15.08.7-1, 0, 14.11.8-4
Ubuntu:Pro:20.04:LTSslurm-llnl19.05.5-1, 0, 19.05.3.2-2
Ubuntu:Pro:18.04:LTSslurm-llnl17.02.6-1build1, 0, 17.11.2-1build1

Timeline

  • May 21, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 18, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›