CVE-2018-20871: Critical severity sun grid engine vulnerability

Published Jul 30, 2019
·
Updated

In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on rootsquash, weak file permissions ("other" write access) occur in certain cases (GE-6890).

Affected Software

1 affected component
Univa Grid Engine=8.6.3

Event History

Jul 30, 2019
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-20871?

CVE-2018-20871 is classified as a medium severity vulnerability due to weak file permissions leading to potential unauthorized write access.

2

How do I fix CVE-2018-20871?

To fix CVE-2018-20871, upgrade Univa Grid Engine to version 8.6.6 or later to ensure proper file permission configurations.

3

What systems are affected by CVE-2018-20871?

CVE-2018-20871 affects Univa Grid Engine versions prior to 8.6.3 that are configured for Docker jobs with execd spooling on root_squash.

4

What risks are associated with CVE-2018-20871?

The risks associated with CVE-2018-20871 include the possibility of unauthorized users gaining write access to sensitive files.

5

Is CVE-2018-20871 a common vulnerability?

CVE-2018-20871 is not commonly reported but poses serious risks for systems using vulnerable versions of Univa Grid Engine.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203