Vulnerability Name:

CVE-2021-43337 (CCN-213669)

Assigned:2021-11-16
Published:2021-11-16
Updated:2022-07-12
Summary:SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2021-43337

Source: XF
Type: UNKNOWN
schedmd-cve202143337-sec-bypass(213669)

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-0611d621ec

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-d82d3d9738

Source: MISC
Type: Mailing List, Vendor Advisory
https://lists.schedmd.com/pipermail/slurm-announce/

Source: CCN
Type: Slurm Mailing List, Tue Nov 16 22:06:22 UTC 2021
Slurm version 21.08.4 is now available (CVE-2021-43337)

Source: CONFIRM
Type: Mailing List, Vendor Advisory
https://lists.schedmd.com/pipermail/slurm-announce/2021/000068.html

Source: MISC
Type: Vendor Advisory
https://www.schedmd.com/news.php

Source: CONFIRM
Type: Patch, Vendor Advisory
https://www.schedmd.com/news.php?id=256

Vulnerable Configuration:Configuration 1:
  • cpe:/a:schedmd:slurm:*:*:*:*:*:*:*:* (Version >= 21.08.0 and < 21.08.4)

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:34:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:35:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:schedmd:slurm:16.05.6:*:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:17.02.0:pre3:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:15.08.12:*:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:17.11.4:*:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:17.02.9:*:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:17.11.12:*:*:*:*:*:x86:*
  • OR cpe:/a:schedmd:slurm:18.08.4:*:*:*:*:*:x86:*
  • OR cpe:/a:schedmd:slurm:18.08.7:*:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:19.05.0:*:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:19.05.4:*:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:20.11.6:*:*:*:*:*:*:*
  • OR cpe:/a:schedmd:slurm:20.02.6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:112726
    P
    libnss_slurm2-21.08.4-1.1 on GA media (Moderate)
    2022-01-17
    BACK
    schedmd slurm *
    fedoraproject fedora 34
    fedoraproject fedora 35
    schedmd slurm 16.05.6
    schedmd slurm 17.02.0 pre3
    schedmd slurm 15.08.12
    schedmd slurm 17.11.4
    schedmd slurm 17.02.9
    schedmd slurm 17.11.12
    schedmd slurm 18.08.4
    schedmd slurm 18.08.7
    schedmd slurm 19.05.0
    schedmd slurm 19.05.4
    schedmd slurm 20.11.6
    schedmd slurm 20.02.6