CVE-2019-19727
Description
Slurm slurmdbd.conf is installed with world-readable permissions, exposing database credentials to local users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Slurm slurmdbd.conf is installed with world-readable permissions, exposing database credentials to local users.
Vulnerability
SchedMD Slurm versions before 18.08.9 and 19.x before 19.05.5 install the slurmdbd.conf configuration file with world-readable permissions (e.g., 0644) instead of the recommended 0600 [1]. This file typically contains the database access password for the SlurmDBD service, making it accessible to any local user on the system.
Exploitation
An attacker with local access to the system where SlurmDBD is installed can read the slurmdbd.conf file without any special privileges. No authentication or user interaction is required beyond having a local user account. The attacker simply reads the file to extract the database credentials.
Impact
Successful exploitation results in disclosure of the database credentials stored in slurmdbd.conf. This can allow the attacker to connect to the Slurm database, potentially leading to unauthorized access, modification, or deletion of job accounting data, user information, and other sensitive records.
Mitigation
The issue is fixed in Slurm versions 18.08.9 and 19.05.5 [1]. Users should upgrade to these or later versions. As a workaround, administrators can manually set the permissions of slurmdbd.conf to 0600 using chmod 0600 /etc/slurm/slurmdbd.conf (or the appropriate path). The SUSE bug report indicates that packaging fixes were applied to ensure correct permissions on installation [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
19- SchedMD/Slurmdescription
- osv-coords17 versionspkg:rpm/opensuse/slurm&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/slurm&distro=openSUSE%20Tumbleweedpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP1pkg:rpm/suse/pdsh_slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_20_11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015pkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP1
< 18.08.9-lp151.2.6.1+ 16 more
- (no CPE)range: < 18.08.9-lp151.2.6.1
- (no CPE)range: < 21.08.1-1.1
- (no CPE)range: < 2.33-7.18.1
- (no CPE)range: < 2.33-7.6.1
- (no CPE)range: < 2.33-7.6.1
- (no CPE)range: < 2.34-7.26.2
- (no CPE)range: < 2.34-7.26.2
- (no CPE)range: < 2.34-7.32.1
- (no CPE)range: < 18.08.9-3.5.1
- (no CPE)range: < 18.08.9-1.5.2
- (no CPE)range: < 20.02.3-3.5.1
- (no CPE)range: < 20.11.4-3.5.1
- (no CPE)range: < 17.11.13-6.31.1
- (no CPE)range: < 17.11.13-6.31.1
- (no CPE)range: < 17.02.11-6.44.1
- (no CPE)range: < 17.11.13-6.23.1
- (no CPE)range: < 18.08.9-3.10.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
4- lists.opensuse.org/opensuse-security-announce/2020-01/msg00038.htmlmitrevendor-advisoryx_refsource_SUSE
- bugzilla.suse.com/show_bug.cgimitrex_refsource_MISC
- lists.schedmd.com/pipermail/slurm-announce/mitrex_refsource_MISC
- www.schedmd.com/news.phpmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.