Database/Control plane, storage & DevOps

Slurm (slurmdbd, AccountingStoreFlags=job_script / job_env): When the site turns on job-script and job-environment
Impact
When the site turns on job-script and job-environment archival, SlurmDBD's access-control rules let a user fetch other users' job scripts and environments. Those routinely contain API keys, model-registry tokens, S3 credentials and dataset paths, so this is a credential harvest across tenants, not just metadata leakage.
Who can reach it
Any user with a Slurm account on a cluster where AccountingStoreFlags includes job_script or job_env. 21.08.0 through 21.08.3 only - the feature did not exist before 21.08.
What to do
Upgrade to Slurm 21.08.4 and restart slurmdbd. If you cannot upgrade now, remove job_script and job_env from AccountingStoreFlags and reconfigure - that removes the exposure immediately. Treat any secret that appeared in a job script or job env during the exposure window as burned and rotate it.
References
Related entries
- IBM Spectrum Scale Data Access Services (DAS): An authenticated DAS user inserts code that manipulates clusterCVE-2022-22411 · IBM Spectrum Scale Data Access Services (DAS)Medium
- FlyteAdmin (external IdP access token / ID token expiration check): FlyteAdmin does not enforce expiry on access and IDCVE-2022-31145 · FlyteAdmin (external IdP access token / ID token expiration check)Medium
- HashiCorp Consul: Internal RPC endpoint does not check multiple SAN URIs in a CSRCVE-2022-40716 · HashiCorp ConsulMedium
- AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003): The IOMMU is not re-initialized during a Dynamic Root ofCVE-2023-20591 · AMD IOMMU - not re-initialized during DRTM (AMD-SB-3003)Medium
- Netdata: Agent MACHINE GUID is readable and reusableCVE-2023-22497 · NetdataMedium
- Apache Guacamole: Miscalculated instruction lengths during the Guacamole handshakeCVE-2023-30575 · Apache GuacamoleMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.