First published: Thu Mar 15 2018(Updated: )
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/slurm-llnl | 18.08.5.2-1+deb10u2 | |
SchedMD Slurm | <17.02.10.0 | |
SchedMD Slurm | >=17.11.0.0<17.11.5.0 | |
SchedMD Slurm | =17.11.0.0-pre1 | |
SchedMD Slurm | =17.11.0.0-pre2 | |
SchedMD Slurm | =17.11.0.0-rc1 | |
SchedMD Slurm | =17.11.0.0-rc2 | |
SchedMD Slurm | =17.11.0.0-rc3 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7033 is a vulnerability in SchedMD Slurm that allows SQL Injection attacks against SlurmDBD.
CVE-2018-7033 has a severity rating of 9.8 (Critical).
Slurm versions before 17.02.10 and 17.11.x before 17.11.5 are affected by CVE-2018-7033.
To fix CVE-2018-7033, upgrade to version 18.08.5.2-1+deb10u2 of the slurm-llnl package for Debian. Alternatively, upgrade to a version above 17.11.5 if you are using SchedMD Slurm.
You can find more information about CVE-2018-7033 at the following references: [link1], [link2], [link3].