跳转到帖子

SUSE: CVE-2023-49935: SUSE Linux Security Advisory

recommended_posts

发布于
  • Members

SUSE: CVE-2023-49935: SUSE Linux Security Advisory

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
12/14/2023
Created
02/02/2024
Added
02/01/2024
Modified
01/28/2025

Description

An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Message Integrity Bypass. An attacker can reuse root-level authentication tokens during interaction with the slurmd process. This bypasses the RPC message hashes that protect against undesired MUNGE credential reuse. The fixed versions are 23.02.7 and 23.11.1.

Solution(s)

  • suse-upgrade-libnss_slurm2
  • suse-upgrade-libnss_slurm2_23_02
  • suse-upgrade-libpmi0
  • suse-upgrade-libpmi0_23_02
  • suse-upgrade-libslurm39
  • suse-upgrade-perl-slurm
  • suse-upgrade-perl-slurm_23_02
  • suse-upgrade-slurm
  • suse-upgrade-slurm-auth-none
  • suse-upgrade-slurm-config
  • suse-upgrade-slurm-config-man
  • suse-upgrade-slurm-cray
  • suse-upgrade-slurm-devel
  • suse-upgrade-slurm-doc
  • suse-upgrade-slurm-hdf5
  • suse-upgrade-slurm-lua
  • suse-upgrade-slurm-munge
  • suse-upgrade-slurm-node
  • suse-upgrade-slurm-openlava
  • suse-upgrade-slurm-pam_slurm
  • suse-upgrade-slurm-plugin-ext-sensors-rrd
  • suse-upgrade-slurm-plugins
  • suse-upgrade-slurm-rest
  • suse-upgrade-slurm-seff
  • suse-upgrade-slurm-sjstat
  • suse-upgrade-slurm-slurmdbd
  • suse-upgrade-slurm-sql
  • suse-upgrade-slurm-sview
  • suse-upgrade-slurm-testsuite
  • suse-upgrade-slurm-torque
  • suse-upgrade-slurm-webdoc
  • suse-upgrade-slurm_23_02
  • suse-upgrade-slurm_23_02-auth-none
  • suse-upgrade-slurm_23_02-config
  • suse-upgrade-slurm_23_02-config-man
  • suse-upgrade-slurm_23_02-cray
  • suse-upgrade-slurm_23_02-devel
  • suse-upgrade-slurm_23_02-doc
  • suse-upgrade-slurm_23_02-lua
  • suse-upgrade-slurm_23_02-munge
  • suse-upgrade-slurm_23_02-node
  • suse-upgrade-slurm_23_02-pam_slurm
  • suse-upgrade-slurm_23_02-plugin-ext-sensors-rrd
  • suse-upgrade-slurm_23_02-plugins
  • suse-upgrade-slurm_23_02-slurmdbd
  • suse-upgrade-slurm_23_02-sql
  • suse-upgrade-slurm_23_02-sview
  • suse-upgrade-slurm_23_02-torque
  • suse-upgrade-slurm_23_02-webdoc

References

  • https://attackerkb.com/topics/cve-2023-49935
  • CVE - 2023-49935
  • 查看数 706
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…