CVE-2020-12693: Debian Linux
High severity, CVSS 8.1. EPSS: 2.3% chance of exploitation in the next 30 days.
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 31 only; version 32 only
- Opensuse Leap: version 15.1 only; version 15.2 only
- Schedmd Slurm: from 19.05.0, before 19.05.7 (fixed in 19.05.7); from 20.02.0, before 20.02.3 (fixed in 20.02.3)
Published 2020-05-21. Last modified 2026-06-17.