Database/Control plane, storage & DevOps

Slurm (openSUSE slurm-testsuite packaging): The openSUSE slurm testsuite package ships files with permissive default
Impact
The openSUSE slurm testsuite package ships files with permissive default ownership, so an attacker who already controls the slurm service account can pivot to root on that host. Since slurmctld runs as SlurmUser, a compromise of the controller daemon becomes a compromise of the controller machine.
Who can reach it
Local, requires already having control of the slurm user - so it is a privilege-escalation chain step after a slurmctld or slurmd compromise, not an entry point.
What to do
Only affects hosts where the openSUSE or SLES slurm-testsuite package is installed. Uninstall it from production controllers - a test suite has no business on a scheduler that runs tenant workloads - or update to the fixed package.
References
Related entries
- Cisco UCS Central Software (weak backup encryption): Weak encryption on full-state and configuration backups meansCVE-2024-20280 · Cisco UCS Central Software (weak backup encryption)Medium
- Dell OpenManage Enterprise (credential disclosure): A low-privileged local user obtains stored credentials from OMECVE-2024-28961 · Dell OpenManage Enterprise (credential disclosure)Medium
- Grafana: org admin can delete other organizations' snapshots and recover delete keys from share keysCVE-2026-19197 · Grafana (dashboard snapshot API)Medium
- CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching): Stack-based buffer overflow in BIRD's AS_PATH maskCVE-2026-49943 · CZ.NIC BIRD Internet Routing Daemon (BGP AS_PATH mask matching)Medium
- Jenkins: agent config update names its own target, letting one agent's configurer take over anotherCVE-2026-84651 · Jenkins controller (REST API and CLI agent configuration update)Medium
- Prometheus (exporter-toolkit): Poisoning the built-in auth cache bypasses basic-auth on exportersCVE-2022-46146 · Prometheus (exporter-toolkit)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.