VYPR

Slurm

by Schedmd

Source repositories

CVEs (25)

  • CVE-2019-19727MedJan 13, 2020
    risk 0.36cvss 5.5epss 0.00

    SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.

  • CVE-2018-10995MedMay 30, 2018
    risk 0.35cvss 5.3epss 0.02

    SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).

  • CVE-2024-48936MedOct 28, 2024
    risk 0.33cvss 5.0epss 0.00

    SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled…

  • CVE-2025-43904MedJan 16, 2026
    risk 0.27cvss 4.2epss 0.00

    In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.

  • CVE-2020-27746LowNov 27, 2020
    risk 0.24cvss 3.7epss 0.01

    Slurm before 19.05.8 and 20.x before 20.02.6 exposes Sensitive Information to an Unauthorized Actor because xauth for X11 magic cookies is affected by a race condition in a read operation on the /proc filesystem.

Page 2 of 2