CVE-2021-31215: High severity slurm workload manager vulnerability
SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31215?
CVE-2021-31215 is a vulnerability in SchedMD Slurm before version 20.02.7 and 20.03.x through 20.11.x before 20.11.7 that allows remote code execution.
How does CVE-2021-31215 allow remote code execution?
CVE-2021-31215 allows remote code execution by mishandling the environment when a PrologSlurmctld or EpilogSlurmctld script is used.
What is the severity of CVE-2021-31215?
CVE-2021-31215 has a severity level of 8.8 (high).
Which software versions are affected by CVE-2021-31215?
CVE-2021-31215 affects SchedMD Slurm versions before 20.02.7 and versions 20.03.x through 20.11.x before 20.11.7.
Are there any references for CVE-2021-31215?
Yes, you can find references for CVE-2021-31215 at the following links: [Link1](https://lists.debian.org/debian-lts-announce/2022/01/msg00011.html) and [Link2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3ODMJQNY4FAV7G3DSKVIO5KY7Q7DKBPU/).