First published: Mon Oct 28 2024(Updated: )
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | <24.05.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48936 is classified as having a high severity due to its potential to allow unauthorized process execution under different user jobs.
To remediate CVE-2024-48936, update SchedMD Slurm to version 24.05.4 or later.
CVE-2024-48936 affects all versions of SchedMD Slurm prior to 24.05.4.
CVE-2024-48936 is an Incorrect Authorization vulnerability within the stepmgr component of SchedMD Slurm.
CVE-2024-48936 requires local access or specific configurations, as it is limited to jobs that are explicitly running with the --stepmgr option.