CVE-2017-15566

Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:*
cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:*
cpe:2.3:a:schedmd:slurm:17.11.0:rc1:*:*:*:*:*:*

History

No history.

Information

Published : 2017-11-01 17:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-15566

Mitre link : CVE-2017-15566

CVE.ORG link : CVE-2017-15566


JSON object : View

Products Affected

schedmd

  • slurm
CWE
CWE-426

Untrusted Search Path