SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
{
"binaries": [
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libpam-slurm"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libpam-slurm-adopt"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libpmi0"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libpmi0-dev"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libpmi2-0"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libpmi2-0-dev"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libslurm-dev"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libslurm-perl"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libslurm37"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "libslurmdb-perl"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurm-client"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurm-client-emulator"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurm-wlm"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurm-wlm-basic-plugins"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurm-wlm-basic-plugins-dev"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurm-wlm-emulator"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurm-wlm-torque"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurmctld"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurmd"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurmdbd"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "slurmrestd"
},
{
"binary_version": "21.08.5-2ubuntu1+esm1",
"binary_name": "sview"
}
]
}