CVE-2022-29500
Description
SchedMD Slurm 21.08.x through 20.11.x contains an incorrect access control vulnerability leading to information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SchedMD Slurm 21.08.x through 20.11.x contains an incorrect access control vulnerability leading to information disclosure.
Vulnerability
SchedMD Slurm versions 21.08.x through 20.11.x have an incorrect access control vulnerability that allows information disclosure. The exact component and conditions are not detailed in available references, but the issue affects the job scheduling and resource management system.
Exploitation
An attacker with network access to the Slurm controller may be able to exploit the incorrect access control to obtain sensitive information. No authentication or user interaction is explicitly required based on available information.
Impact
Successful exploitation leads to information disclosure, potentially exposing configuration details or job data that should be restricted.
Mitigation
No specific fix version is identified in the available references. Users should monitor SchedMD releases for a patch. As of the publication date (2022-05-05), no fixed version has been announced.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
75- osv-coords73 versionspkg:rpm/opensuse/pdsh&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/pdsh&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/pdsh_slurm_20_02&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/pdsh_slurm_20_02&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/pdsh_slurm_20_11&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/pdsh_slurm_20_11&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/pdsh_slurm_22_05&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/pdsh_slurm_22_05&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_18_08&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm_18_08&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_20_02&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm_20_02&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_20_11&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm_20_11&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_22_05&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm_22_05&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm_23_02&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/slurm&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/slurm&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3pkg:rpm/suse/pdsh&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/pdsh_slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_20_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/pdsh_slurm_20_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/pdsh_slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_20_11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3pkg:rpm/suse/pdsh_slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/slurm_18_08&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm_20_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/slurm_20_11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3pkg:rpm/suse/slurm_22_05&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/slurm_23_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm_23_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/slurm_23_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/slurm_23_02&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/slurm_23_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm_23_02&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP4pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP3pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2015%20SP5pkg:rpm/suse/slurm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5
< 2.34-150300.35.2+ 72 more
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 18.08.9-150000.1.17.1
- (no CPE)range: < 18.08.9-150000.1.17.1
- (no CPE)range: < 20.02.7-150100.3.24.1
- (no CPE)range: < 20.02.7-150100.3.24.1
- (no CPE)range: < 20.11.9-150200.6.10.1
- (no CPE)range: < 20.11.9-150200.6.10.1
- (no CPE)range: < 22.05.5-150300.7.3.2
- (no CPE)range: < 22.05.5-150300.7.3.2
- (no CPE)range: < 23.02.5-150300.7.11.2
- (no CPE)range: < 20.11.9-150300.4.6.1
- (no CPE)range: < 20.11.9-150300.4.6.1
- (no CPE)range: < 23.02.5-150500.5.9.2
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-7.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-7.35.3
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-7.35.3
- (no CPE)range: < 2.34-7.35.3
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150100.10.14.1
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-150200.4.6.2
- (no CPE)range: < 2.34-7.35.5
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 2.34-150300.35.2
- (no CPE)range: < 18.08.9-150000.1.17.1
- (no CPE)range: < 18.08.9-150000.1.17.1
- (no CPE)range: < 18.08.9-3.17.1
- (no CPE)range: < 20.02.7-150100.3.24.1
- (no CPE)range: < 20.02.7-150100.3.24.1
- (no CPE)range: < 20.02.7-3.14.1
- (no CPE)range: < 20.11.9-150100.3.14.1
- (no CPE)range: < 20.11.9-150100.3.14.1
- (no CPE)range: < 20.11.9-150200.6.10.1
- (no CPE)range: < 20.11.9-150200.6.10.1
- (no CPE)range: < 20.11.9-3.11.1
- (no CPE)range: < 22.05.5-150100.3.3.1
- (no CPE)range: < 22.05.5-150100.3.3.1
- (no CPE)range: < 22.05.5-150200.5.3.2
- (no CPE)range: < 22.05.5-150200.5.3.2
- (no CPE)range: < 22.05.5-3.3.5
- (no CPE)range: < 22.05.5-150300.7.3.2
- (no CPE)range: < 22.05.5-150300.7.3.2
- (no CPE)range: < 23.02.5-150100.3.11.2
- (no CPE)range: < 23.02.5-150200.5.11.2
- (no CPE)range: < 23.02.5-150300.7.11.2
- (no CPE)range: < 23.02.5-150300.7.11.2
- (no CPE)range: < 23.02.5-3.10.6
- (no CPE)range: < 23.02.5-150300.7.11.2
- (no CPE)range: < 18.08.9-150100.3.22.1
- (no CPE)range: < 18.08.9-150100.3.22.1
- (no CPE)range: < 20.02.7-150200.3.14.2
- (no CPE)range: < 20.02.7-150200.3.14.2
- (no CPE)range: < 17.11.13-150000.6.40.1
- (no CPE)range: < 17.11.13-150000.6.40.1
- (no CPE)range: < 17.02.11-6.53.1
- (no CPE)range: < 20.11.9-150300.4.6.1
- (no CPE)range: < 23.02.5-150500.5.9.2
- (no CPE)range: < 23.02.5-150500.5.9.2
Patches
0No patches discovered yet.
Vulnerability mechanics
Root cause
"Incorrect access control in Slurm allows unauthorized information disclosure."
Attack vector
An attacker with network access to a Slurm cluster can exploit missing or insufficient access control checks to read information they should not be authorized to see [ref_id=1]. The advisory does not detail the specific RPC endpoint, payload shape, or authentication preconditions required. The vulnerability is present in Slurm versions 20.11.x through 21.08.x [ref_id=1].
Affected code
The advisory does not specify the exact functions or files at fault. It only states that Slurm versions 20.11.x through 21.08.x contain an "Incorrect Access Control" issue leading to information disclosure [ref_id=1]. No patch or code diff is provided in the bundle.
What the fix does
The advisory does not include a patch or specific remediation steps [ref_id=1]. The vendor (SchedMD) has not published a fix in the referenced release notes page. Users are advised to consult the SchedMD news page for future updates addressing this issue [ref_id=1].
Preconditions
- networkNetwork access to a Slurm cluster running version 20.11.x through 21.08.x
Generated on May 28, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
7- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HXLOI3ERTKMZR2KWNRN7OR5S55VPWENH/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y6B7OWVNVCJUDE6VDWGCBUWMRCRETAO3/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YBI4NFDGGMBKWG4EMSZL5UHATDCLPCQW/mitrevendor-advisoryx_refsource_FEDORA
- www.debian.org/security/2022/dsa-5166mitrevendor-advisoryx_refsource_DEBIAN
- lists.schedmd.com/pipermail/slurm-announce/mitrex_refsource_MISC
- www.schedmd.com/news.phpmitrex_refsource_MISC
- www.schedmd.com/news.phpmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.