VDB
CVE-2024-48936
CVE-2024-48936
PUBLISHED
CVSS 5 MEDIUM
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
EPSS 0.35% · 27.9th percentile
Risk Scores
CVSS 3.1
5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.35%
27.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a, n/a |
| schedmd | slurm | 0, 0 |
Timeline
- Oct 28, 2024 CVE Published
- Oct 28, 2024 EPSS Score
- Oct 28, 2024 Coalition ESS Score
- Oct 28, 2024 Coalition ESS Score
- Oct 28, 2024 PoC Published
- Oct 30, 2024 Coalition ESS Score
- Nov 15, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Dec 23, 2024 EPSS Score
- Jan 10, 2025 EPSS Score
- Jan 29, 2025 EPSS Score
- Feb 16, 2025 EPSS Score
References
- https://lists.schedmd.com/mailman3/hyperkitty/list/slurm-announce%40lists.schedmd.com/message/44MFMN7R35YZFWTNO43R2754W5B5XUAI/ mailing_list
- https://www.schedmd.com/security-policy/ vendor
- https://nvd.nist.gov/vuln/detail/CVE-2024-48936 advisory
- https://lists.schedmd.com/mailman3/hyperkitty/list/slurm-announce%40lists.schedmd.com/message/44MFMN7R35YZFWTNO43R2754W5B5XUAI url
- https://lists.schedmd.com/pipermail/slurm-announce/2024/date.html url
- https://www.schedmd.com/security-policy url