SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
{ "binaries": [ { "binary_name": "libpam-slurm", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libpam-slurm-adopt", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libpmi0", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libpmi0-dev", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libpmi2-0", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libpmi2-0-dev", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libslurm-dev", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libslurm-perl", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libslurm37", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "libslurmdb-perl", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurm-client", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurm-client-emulator", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurm-wlm", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurm-wlm-basic-plugins", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurm-wlm-basic-plugins-dev", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurm-wlm-emulator", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurm-wlm-torque", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurmctld", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurmd", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurmdbd", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "slurmrestd", "binary_version": "21.08.5-2ubuntu1" }, { "binary_name": "sview", "binary_version": "21.08.5-2ubuntu1" } ] }