SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
{ "binaries": [ { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libpam-slurm" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libpam-slurm-adopt" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libpmi0" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libpmi0-dev" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libpmi2-0" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libpmi2-0-dev" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libslurm-dev" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libslurm-perl" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libslurm37" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "libslurmdb-perl" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurm-client" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurm-client-emulator" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurm-wlm" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurm-wlm-basic-plugins" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurm-wlm-basic-plugins-dev" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurm-wlm-emulator" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurm-wlm-torque" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurmctld" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurmd" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurmdbd" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "slurmrestd" }, { "binary_version": "21.08.5-2ubuntu1", "binary_name": "sview" } ] }