CVE-2024-48936

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2024
Last modified:
17/04/2025

Description

SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:* 24.05.4 (excluding)