Known vulnerabilities in Slurm

Vendor: SchedMD
Software: Slurm
Software CPE: cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:*
Total vulnerabilities: 22
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Slurm Slurm is affected by 22 known vulnerabilities: 6 high, 7 medium, 9 low Critical High Medium Low

Vulnerabilities (22)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU84787 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-49934
CWE-89 High
No
No
23.11.1.1 26.12.2023 SB2023122628
SB2023122706
SB2023122707
and 1 more
#VU84786 - Insufficient Session Expiration
CVE-2023-49935
CWE-613 High
No
No
23.02.7.1, 23.11.1.1 26.12.2023 SB2023122628
SB2023122706
SB2023122707
and 5 more
#VU84785 - NULL Pointer Dereference
CVE-2023-49936
CWE-476 Medium
No
No
22.05.11.1, 23.02.7.1, 23.11.1.1 26.12.2023 SB2023122628
SB2023122706
SB2023122707
and 18 more
#VU84784 - Double Free
CVE-2023-49937
CWE-415 High
No
No
22.05.11.1, 23.02.7.1, 23.11.1.1 26.12.2023 SB2023122628
SB2023122706
SB2023122707
and 18 more
#VU84783 - Improper Access Control
CVE-2023-49938
CWE-284 Low
No
No
22.05.11.1, 23.02.7.1 26.12.2023 SB2023122628
SB2023122706
SB2023122707
and 18 more
#VU84782 - Improper Enforcement of Message Integrity During Transmission in a Communication Channel
CVE-2023-49933
CWE-924 Medium
No
No
22.05.11.1, 23.02.7.1, 23.11.1.1 26.12.2023 SB2023122628
SB2023122706
SB2023122707
and 18 more
#VU82228 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2023-41914
CWE-362 Low
No
No
22.05.10.1, 23.02.6.1 18.10.2023 SB20231018127
SB20231018129
SB20231018130
and 26 more
#VU62865 - Improper Access Control
CVE-2022-29500
CWE-284 Medium
No
No
20.11.9, 21.08.8 09.05.2022 SB2022050908
SB2022062037
SB2022092834
and 17 more
#VU62864 - Improper Access Control
CVE-2022-29501
CWE-284 High
No
No
20.11.9, 21.08.8 09.05.2022 SB2022050908
SB2022062037
SB2022092834
and 18 more
#VU62863 - Improper Access Control
CVE-2022-29502
CWE-284 Medium
No
No
20.11.9, 21.08.8 09.05.2022 SB2022050908
SB2023103050
SB2022050541
and 3 more
#VU53685 - Permissions, Privileges, and Access Controls
CVE-2021-31215
CWE-264 Medium
No
No
20.02.7.1, 20.11.7.1 01.06.2021 SB2021060102
SB2021052732
SB2021052733
and 17 more
#VU50142 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2020-27746
CWE-362 Low
No
No
19.05.8.1, 20.02.6.1 27.11.2020 SB2020112720
SB2021012911
SB2023020128
and 4 more
#VU50143 - Memory corruption
CVE-2020-27745
CWE-119 Low
No
No
19.05.8.1, 20.02.6.1 27.11.2020 SB2020112720
SB2021012911
SB2023020128
and 4 more
#VU46672 - Authentication Bypass Using an Alternate Path or Channel
CVE-2020-12693
CWE-288 High
No
No
19.05.7.1, 20.02.3.1 14.09.2020 SB2020052230
SB2020091408
SB2020091903
and 6 more
#VU50141 - Improper Privilege Management
CVE-2019-19728
CWE-269 Low
No
No
18.08.9.1, 19.05.5.1 13.01.2020 SB2021012910
SB2021012911
SB2021031223
and 2 more
#VU50144 - Incorrect Permission Assignment for Critical Resource
CVE-2019-19727
CWE-732 Low
No
No
18.08.9.1, 19.05.5.1 13.01.2020 SB2021012910
SB2021031223
SB2019122370
and 1 more
#VU20855 - Heap-based Buffer Overflow
CVE-2019-6438
CWE-122 Medium
No
No
17.11.13.1, 18.08.5.1 04.09.2019 SB2019013119
SB2019042408
SB2023020128
and 3 more
#VU20853 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-12838
CWE-89 Medium
No
No
18.08.8.1, 19.05.1.1 04.09.2019 SB2019090414
SB2019090415
SB2019111917
and 4 more
#VU37992 - Untrusted Search Path
CVE-2017-15566
CWE-426 Low
No
No
- 01.11.2017 SB2017110109
SB2023020128
SB2021031223
and 1 more
#VU39953 - Improper Access Control
CVE-2016-10030
CWE-284 High
No
No
- 05.01.2017 SB2017010504
SB2023020128
SB2021031223


Showing elements 1 - 20 out of 22