Database/Control plane, storage & DevOps

Slurm (slurmdbd.conf file permissions): slurmdbd.conf is installed world-readable, which leaks the accounting
Impact
slurmdbd.conf is installed world-readable, which leaks the accounting database's credentials to every local account on the host. Whoever reads it connects to MySQL as slurmdbd and owns the accounting data directly, bypassing Slurm entirely.
Who can reach it
Any local user on the host running slurmdbd - which on smaller clusters is the same box as slurmctld or even a login node.
What to do
Upgrade to Slurm 18.08.9 or 19.05.5, then chmod 600 slurmdbd.conf and chown it to the SlurmUser. Rotate the database password too - assume it was readable for the whole time the file sat at the default mode.
References
Related entries
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (improper input validation) reachableCVE-2020-24502 · Intel E810 adapter driver for Linux (< 1.0.4)Medium
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (insufficient access control leadingCVE-2020-24503 · Intel E810 adapter driver for Linux (< 1.0.4)Medium
- Intel E810 adapter driver for Linux (< 1.0.4): Early E810 Linux driver flaw (uncontrolled resource consumption)CVE-2020-24504 · Intel E810 adapter driver for Linux (< 1.0.4)Medium
- IBM Spectrum Scale mmfsd daemon (RPC request handling): A local attacker floods mmfsd with RPC requests and crashes itCVE-2020-4491 · IBM Spectrum Scale mmfsd daemon (RPC request handling)Medium
- AMD CPU core logic - core hang triggered from an unprivileged VM: Specific code executed from an unprivileged VM canCVE-2021-26339 · AMD CPU core logic - core hang triggered from an unprivileged VMMedium
- AMD AGESA Boot Loader (ABL) / ASP stage-2 bootloader: A malicious or compromised User Application or AGESA Boot LoaderCVE-2021-26361 · AMD AGESA Boot Loader (ABL) / ASP stage-2 bootloaderMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.