CVE-2020-12693: Race Condition
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12693?
The severity of CVE-2020-12693 is high with a severity value of 8.1.
Which versions of Slurm are affected by CVE-2020-12693?
Slurm versions 19.05.x before 19.05.7 and 20.02.x before 20.02.3 are affected by CVE-2020-12693.
How can an authentication bypass via an alternate path or channel be achieved in CVE-2020-12693?
In rare cases where Message Aggregation is enabled, a race condition allows a user to launch a process as an arbitrary user, resulting in an authentication bypass via an alternate path or channel in CVE-2020-12693.
Which software packages are affected by CVE-2020-12693?
The Slurm packages 'slurm-llnl' and 'slurm-wlm' are affected by CVE-2020-12693.
How can I fix CVE-2020-12693?
To fix CVE-2020-12693, update Slurm to versions 19.05.7 or 20.02.3 or apply the necessary updates provided by the respective software vendors.