CVE-2024-48936: Schedmd Slurm
Medium severity, CVSS 5.0. EPSS: 0.4% chance of exploitation in the next 30 days.
SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users' jobs. This is limited to jobs explicitly running with --stepmgr, or on systems that have globally enabled stepmgr via SlurmctldParameters=enable_stepmgr in their configuration.
Affected products
- Schedmd Slurm: before 24.05.4 (fixed in 24.05.4)
Published 2024-10-28. Last modified 2026-06-17.