CVE-2018-7033: SQL Injection
SchedMD Slurm before 17.02.10 and 17.11.x before 17.11.5 allows SQL Injection attacks against SlurmDBD.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/slurm-llnlto a version that resolves this vulnerability.Fixed in 18.08.5.2-1+deb10u2
Event History
Frequently Asked Questions
What is CVE-2018-7033?
CVE-2018-7033 is a vulnerability in SchedMD Slurm that allows SQL Injection attacks against SlurmDBD.
What is the severity of CVE-2018-7033?
CVE-2018-7033 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2018-7033?
Slurm versions before 17.02.10 and 17.11.x before 17.11.5 are affected by CVE-2018-7033.
How can I fix CVE-2018-7033?
To fix CVE-2018-7033, upgrade to version 18.08.5.2-1+deb10u2 of the slurm-llnl package for Debian. Alternatively, upgrade to a version above 17.11.5 if you are using SchedMD Slurm.
Where can I find more information about CVE-2018-7033?
You can find more information about CVE-2018-7033 at the following references: [link1], [link2], [link3].