High severity8.1NVD Advisory· Published May 21, 2020· Updated Jun 17, 2026
CVE-2020-12693
CVE-2020-12693
Description
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19- Slurm/Slurmdescription
- osv-coords17 versionspkg:rpm/opensuse/slurm&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/slurm&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/slurm&distro=openSUSE%20Tumbleweedpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_20_11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP1pkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP1
< 18.08.9-lp151.2.10.1+ 16 more
- (no CPE)range: < 18.08.9-lp151.2.10.1
- (no CPE)range: < 18.08.9-lp152.2.1
- (no CPE)range: < 21.08.1-1.1
- (no CPE)range: < 2.34-7.32.1
- (no CPE)range: < 2.34-7.26.2
- (no CPE)range: < 2.34-7.26.2
- (no CPE)range: < 2.34-7.32.1
- (no CPE)range: < 18.08.9-1.8.2
- (no CPE)range: < 18.08.9-1.8.2
- (no CPE)range: < 18.08.9-3.8.1
- (no CPE)range: < 20.02.3-3.5.1
- (no CPE)range: < 20.02.3-3.8.1
- (no CPE)range: < 20.11.4-3.5.1
- (no CPE)range: < 17.11.13-6.31.1
- (no CPE)range: < 17.11.13-6.31.1
- (no CPE)range: < 17.02.11-6.44.1
- (no CPE)range: < 18.08.9-3.13.2
Patches
Vulnerability mechanics
References
8- lists.opensuse.org/opensuse-security-announce/2020-09/msg00035.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-09/msg00063.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/01/msg00011.htmlnvdMailing ListThird Party Advisory
- lists.schedmd.com/pipermail/slurm-announce/2020/000036.htmlnvdMailing ListRelease NotesVendor Advisory
- www.debian.org/security/2021/dsa-4841nvdThird Party Advisory
- www.schedmd.com/news.phpnvdVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNL5E5SK4WP6M3DKU4IKW2NPQD2XTZ4Y/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3RGQB3EWDLOLTSPAJPPWZEPQK3O3AUH/nvd
News mentions
0No linked articles in our index yet.