Vulnerability identifier: #VU84783
Vulnerability risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-49938
CWE-ID:
CWE-284
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Slurm
Server applications /
Remote management servers, RDP, SSH
Vendor: SchedMD
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can modify extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Slurm: 22.05.0.1 - 22.05.10.1, 23.02.0.1 - 23.02.6.1
External links
https://lists.schedmd.com/pipermail/slurm-announce/2023/000103.html
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.