Database/Control plane, storage & DevOps

Slurm (X11 forwarding, xauth magic-cookie setup): Slurm shells out to xauth to install a user's X11 magic cookie, and
Impact
Slurm shells out to xauth to install a user's X11 magic cookie, and there is a window where the cookie is visible under /proc. A co-tenant polling /proc on the same node steals the cookie and attaches to that user's X11 session - keystrokes, screen contents, and the ability to inject input.
Who can reach it
A co-tenant with a job or shell on the same compute node as a victim who submitted with --x11. Only jobs that requested X11 forwarding are exposed.
What to do
Upgrade to Slurm 19.05.8 or 20.02.6 and restart slurmd. If you cannot upgrade, disable X11 forwarding (PrologFlags without X11) - on a GPU training cluster X11 forwarding is almost never load-bearing and turning it off is cheap.
References
Related entries
- Zabbix: Some setup.php steps reachable by unauthenticated usersCVE-2022-23134 · ZabbixLow
- SkyPilot (sky/users/server.py, user ID derivation from username): User IDs are derived with a weak hash of theCVE-2026-13482 · SkyPilot (sky/users/server.py, user ID derivation from username)Low
- GitLab: unauthenticated GraphQL requests can read CI/CD job traces containing secret variable valuesCVE-2026-4523 · GitLab CE/EE (GraphQL API, CI/CD job traces)Low
- NATS server (TLS ciphersuite selection via CLI flags): A configuration footgun in the cluster message bus: NATSNCVD-2021-017-nats-server-tls-ciphersuite-sele · NATS server (TLS ciphersuite selection via CLI flags)Low
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM determines whether data exists on aCVE-2020-8588 · NetApp Clustered Data ONTAP Storage Virtual Machine boundaryLow
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM enumerates the names of other SVMs andCVE-2020-8589 · NetApp Clustered Data ONTAP Storage Virtual Machine boundaryLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.