SQL injection in Slurm - CVE-2018-7033

 

SQL injection in Slurm - CVE-2018-7033

Published: July 25, 2018 / Updated: July 25, 2018


Vulnerability identifier: #VU13996
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7033
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL commands in web application database.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted HTTP request to vulnerable script and execute arbitrary SQL commands in web application database.

Successful exploitation of the vulnerability may allow an attacker to gain administrative access to vulnerable web application.


Affected software

Slurm
Debian Linux
SUSE Linux Enterprise Module for HPC
Ubuntu
Fedora
libslurm-perl (Ubuntu package)
slurmctld (Ubuntu package)
slurm-llnl-sview (Ubuntu package)
slurm-llnl-torque (Ubuntu package)
slurm-llnl-basic-plugins (Ubuntu package)
libslurm26 (Ubuntu package)
libslurmdb26 (Ubuntu package)
slurm-wlm-basic-plugins (Ubuntu package)
sview (Ubuntu package)
libslurmdb-perl (Ubuntu package)
slurm-llnl-slurmdbd (Ubuntu package)
slurmdbd (Ubuntu package)
libslurmdb29 (Ubuntu package)
slurm-llnl (Ubuntu package)
libslurm29 (Ubuntu package)
libpmi0 (Ubuntu package)
slurm-wlm (Ubuntu package)
slurm-client (Ubuntu package)
libpam-slurm (Ubuntu package)
slurmd (Ubuntu package)
slurm-wlm-torque (Ubuntu package)
slurm-client-emulator (Ubuntu package)
slurm-wlm-emulator (Ubuntu package)
pdsh-machines-debuginfo
pdsh-netgroup
pdsh-netgroup-debuginfo
pdsh-slurm
pdsh-slurm-debuginfo
pdsh-slurm_18_08
pdsh-slurm_18_08-debuginfo
pdsh-slurm_20_02
pdsh-slurm_20_02-debuginfo
pdsh-slurm_20_11
pdsh-slurm_20_11-debuginfo
pdsh_slurm_18_08-debugsource
pdsh_slurm_20_02-debugsource
pdsh_slurm_20_11-debugsource
pdsh-genders-debuginfo
pdsh-genders
pdsh-dshgroup-debuginfo
pdsh-dshgroup
pdsh-debugsource
pdsh-debuginfo
pdsh
pdsh-machines
slurm
slurm_20_11-sql
slurm_20_11-node
slurm_20_11-node-debuginfo
slurm_20_11-pam_slurm
slurm_20_11-pam_slurm-debuginfo
slurm_20_11-plugins
slurm_20_11-plugins-debuginfo
slurm_20_11-slurmdbd
slurm_20_11-slurmdbd-debuginfo
slurm_20_11-munge-debuginfo
slurm_20_11-sql-debuginfo
slurm_20_11-sview
slurm_20_11-sview-debuginfo
slurm_20_11-torque
slurm_20_11-torque-debuginfo
slurm_20_11-webdoc
libslurm36
libslurm36-debuginfo
slurm_20_11-config
libpmi0_20_11
libnss_slurm2_20_11-debuginfo
libnss_slurm2_20_11
perl-slurm_20_11
perl-slurm_20_11-debuginfo
slurm_20_11
slurm_20_11-auth-none
slurm_20_11-auth-none-debuginfo
libpmi0_20_11-debuginfo
slurm_20_11-config-man
slurm_20_11-debuginfo
slurm_20_11-debugsource
slurm_20_11-devel
slurm_20_11-doc
slurm_20_11-lua
slurm_20_11-lua-debuginfo
slurm_20_11-munge

How to mitigate CVE-2018-7033

The vulnerability is addressed in the versions 17.02.10, 17.11.5.

Slurm - addressed in versions 17.02.10, 17.11.5
libslurm-perl (Ubuntu package) - update to Ubuntu Pro
slurmctld (Ubuntu package) - update to Ubuntu Pro
slurm-llnl-sview (Ubuntu package) - update to Ubuntu Pro
slurm-llnl-torque (Ubuntu package) - update to Ubuntu Pro
slurm-llnl-basic-plugins (Ubuntu package) - update to Ubuntu Pro
libslurm26 (Ubuntu package) - update to Ubuntu Pro
libslurmdb26 (Ubuntu package) - update to Ubuntu Pro
slurm-wlm-basic-plugins (Ubuntu package) - update to Ubuntu Pro
sview (Ubuntu package) - update to Ubuntu Pro
libslurmdb-perl (Ubuntu package) - update to Ubuntu Pro
slurm-llnl-slurmdbd (Ubuntu package) - update to Ubuntu Pro
slurmdbd (Ubuntu package) - update to Ubuntu Pro
libslurmdb29 (Ubuntu package) - update to Ubuntu Pro
slurm-llnl (Ubuntu package) - update to Ubuntu Pro
libslurm29 (Ubuntu package) - update to Ubuntu Pro
libpmi0 (Ubuntu package) - update to Ubuntu Pro
slurm-wlm (Ubuntu package) - update to Ubuntu Pro
slurm-client (Ubuntu package) - update to Ubuntu Pro
libpam-slurm (Ubuntu package) - update to Ubuntu Pro
slurmd (Ubuntu package) - update to Ubuntu Pro
slurm-wlm-torque (Ubuntu package) - update to Ubuntu Pro
slurm-client-emulator (Ubuntu package) - update to Ubuntu Pro
slurm-wlm-emulator (Ubuntu package) - update to Ubuntu Pro
pdsh-machines-debuginfo - update to 2.34-7.32.1
pdsh-netgroup - update to 2.34-7.32.1
pdsh-netgroup-debuginfo - update to 2.34-7.32.1
pdsh-slurm - update to 2.34-7.32.1
pdsh-slurm-debuginfo - update to 2.34-7.32.1
pdsh-slurm_18_08 - update to 2.34-7.32.1
pdsh-slurm_18_08-debuginfo - update to 2.34-7.32.1
pdsh-slurm_20_02 - update to 2.34-7.32.1
pdsh-slurm_20_02-debuginfo - update to 2.34-7.32.1
pdsh-slurm_20_11 - update to 2.34-7.32.1
pdsh-slurm_20_11-debuginfo - update to 2.34-7.32.1
pdsh_slurm_18_08-debugsource - update to 2.34-7.32.1
pdsh_slurm_20_02-debugsource - update to 2.34-7.32.1
pdsh_slurm_20_11-debugsource - update to 2.34-7.32.1
pdsh-genders-debuginfo - update to 2.34-7.32.1
pdsh-genders - update to 2.34-7.32.1
pdsh-dshgroup-debuginfo - update to 2.34-7.32.1
pdsh-dshgroup - update to 2.34-7.32.1
pdsh-debugsource - update to 2.34-7.32.1
pdsh-debuginfo - update to 2.34-7.32.1
pdsh - update to 2.34-7.32.1
pdsh-machines - update to 2.34-7.32.1
slurm - addressed in versions 17.02.10-1.fc27, 17.11.5-2.fc28
slurm_20_11-sql - update to 20.11.4-3.5.1
slurm_20_11-node - update to 20.11.4-3.5.1
slurm_20_11-node-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-pam_slurm - update to 20.11.4-3.5.1
slurm_20_11-pam_slurm-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-plugins - update to 20.11.4-3.5.1
slurm_20_11-plugins-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-slurmdbd - update to 20.11.4-3.5.1
slurm_20_11-slurmdbd-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-munge-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-sql-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-sview - update to 20.11.4-3.5.1
slurm_20_11-sview-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-torque - update to 20.11.4-3.5.1
slurm_20_11-torque-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-webdoc - update to 20.11.4-3.5.1
libslurm36 - update to 20.11.4-3.5.1
libslurm36-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-config - update to 20.11.4-3.5.1
libpmi0_20_11 - update to 20.11.4-3.5.1
libnss_slurm2_20_11-debuginfo - update to 20.11.4-3.5.1
libnss_slurm2_20_11 - update to 20.11.4-3.5.1
perl-slurm_20_11 - update to 20.11.4-3.5.1
perl-slurm_20_11-debuginfo - update to 20.11.4-3.5.1
slurm_20_11 - update to 20.11.4-3.5.1
slurm_20_11-auth-none - update to 20.11.4-3.5.1
slurm_20_11-auth-none-debuginfo - update to 20.11.4-3.5.1
libpmi0_20_11-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-config-man - update to 20.11.4-3.5.1
slurm_20_11-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-debugsource - update to 20.11.4-3.5.1
slurm_20_11-devel - update to 20.11.4-3.5.1
slurm_20_11-doc - update to 20.11.4-3.5.1
slurm_20_11-lua - update to 20.11.4-3.5.1
slurm_20_11-lua-debuginfo - update to 20.11.4-3.5.1
slurm_20_11-munge - update to 20.11.4-3.5.1

External References

Related Security Bulletins