Database/Control plane, storage & DevOps

Slurm (user_name / gid field handling): Slurm trusts the user_name and gid fields carried in job RPCs instead of
Impact
Slurm trusts the user_name and gid fields carried in job RPCs instead of resolving identity itself, so the identity a job runs under can be steered by whoever crafts the RPC. On a shared cluster that is the first half of running work under someone else's account.
Who can reach it
A tenant who can submit jobs, or anyone who can talk to slurmctld or slurmd on the cluster network.
What to do
Upgrade to Slurm 17.02.11 or 17.11.7 and restart slurmctld and slurmd. Pair the upgrade with a check that MUNGE is actually enforcing authentication on every node - this class of bug is only dangerous when the RPC path is not independently authenticated.
References
Related entries
- IBM Spectrum LSF (job submission, file permissions): Weak file permissions in the LSF install let a local user changeCVE-2018-1724 · IBM Spectrum LSF (job submission, file permissions)Medium
- AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016): Insufficient RMP checking on IOMMU host bufferCVE-2023-20585 · AMD IOMMU host buffer access - insufficient RMP checks (AMD-SB-3016)Medium
- ZKTeco BioAccess IVS v3.3.1 access control platform: An unauthenticated attacker can open and close any doorCVE-2023-38958 · ZKTeco BioAccess IVS v3.3.1 access control platformMedium
- Intel Data Center GPU Flex Series - Windows driver software: Improper access control in the Flex Series Windows driverCVE-2024-43101 · Intel Data Center GPU Flex Series - Windows driver softwareMedium
- Grafana: Org Admin can read dashboard permission mappings belonging to other organizationsCVE-2026-11817 · Grafana access-control API (/api/access-control/users/permissions/search), multi-org stacksMedium
- OpenChoreo: autobuild webhook picks its provider from a caller-supplied header and accepts unsigned Bitbucket requestsCVE-2026-73840 · OpenChoreo API (POST /api/v1alpha1/autobuild webhook handler)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.