CVE-2019-19728: High severity slurm workload manager vulnerability
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19728?
CVE-2019-19728 is a vulnerability in SchedMD Slurm before version 18.08.9 and 19.x before version 19.05.5 that allows execution of srun --uid with incorrect privileges.
What is the severity of CVE-2019-19728?
CVE-2019-19728 has a severity level of high, with a severity value of 7.5.
How does CVE-2019-19728 affect SchedMD Slurm?
CVE-2019-19728 affects SchedMD Slurm versions before 18.08.9 and 19.x before 19.05.5, allowing the execution of srun --uid with incorrect privileges.
What is the fix for CVE-2019-19728?
To fix CVE-2019-19728, users should update to SchedMD Slurm version 18.08.9 or 19.05.5.
Are there any references for CVE-2019-19728?
Yes, you can find more information about CVE-2019-19728 at the following references: [https://github.com/SchedMD/slurm/commit/5ac031b2ef5462f6e8e47dad0247bd474614c118](reference 1), [https://bugzilla.suse.com/show_bug.cgi?id=1159692](reference 2), [https://bugs.schedmd.com/show_bug.cgi?id=8084](reference 3).