CVE-2009-2084

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
16/06/2009
Last modified:
09/04/2025

Description

Simple Linux Utility for Resource Management (SLURM) 1.2 and 1.3 before 1.3.14 does not properly set supplementary groups before invoking (1) sbcast from the slurmd daemon or (2) strigger from the slurmctld daemon, which might allow local SLURM users to modify files and gain privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:llnl:slurm:*:*:*:*:*:*:*:* 1.3.13 (including)
cpe:2.3:a:llnl:slurm:1.2:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.4:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.5:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.6:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.7:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.8:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.9:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.10:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.11:*:*:*:*:*:*:*
cpe:2.3:a:llnl:slurm:1.3.12:*:*:*:*:*:*:*