CVE-2017-15566 Information
Feb 14, 2021
cve
Description
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11 17.x before 17.02.9 and 17.11.x before 17.11.0rc2 allowing privilege escalation to root during Prolog or Epilog execution.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/101675 https://www.debian.org/security/2017/dsa-4023 https://www.schedmd.com/news.php?id=193OPT_193
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: