Candidate: CVE-2020-12693 PublicDate: 2020-05-21 23:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12693 https://www.schedmd.com/news.php?id=236 https://lists.schedmd.com/pipermail/slurm-announce/2020/000036.html Description: Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=961406 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H [8.1 HIGH] Patches_slurm-llnl: upstream_slurm-llnl: needs-triage precise/esm_slurm-llnl: DNE trusty_slurm-llnl: ignored (out of standard support) trusty/esm_slurm-llnl: not-affected (code not present) xenial_slurm-llnl: ignored (end of standard support, was needs-triage) bionic_slurm-llnl: needed eoan_slurm-llnl: DNE focal_slurm-llnl: needed groovy_slurm-llnl: ignored (reached end-of-life) hirsute_slurm-llnl: DNE impish_slurm-llnl: DNE jammy_slurm-llnl: DNE devel_slurm-llnl: DNE