CVE-2018-10995
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
30/05/2018
Last modified:
03/10/2019
Description
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:* | 17.02.10.1 (including) | |
| cpe:2.3:a:schedmd:slurm:17.11.0.0:pre1:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.0.0:pre2:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.0.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.0.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.0.0:rc3:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.3.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.3.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.5.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:schedmd:slurm:17.11.6.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



