CVE-2021-43337

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/11/2021
Last modified:
07/11/2023

Description

SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:* 21.08.0 (including) 21.08.4 (excluding)
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*