CVE-2020-12693
Last modified
CVE-2020-12693 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.. EPSS estimates a 2.26% chance of exploitation in the next 30 days.
Description
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schedmd | Slurm | >= 19.05.0, < 19.05.7 |
| Schedmd | Slurm | >= 20.02.0, < 20.02.3 |
| Fedoraproject | Fedora | 31 |
| Fedoraproject | Fedora | 32 |
| Opensuse | Leap | 15.1 |
| Opensuse | Leap | 15.2 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00035.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00063.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00011.htmlMailing List, Third Party Advisory
- https://lists.schedmd.com/pipermail/slurm-announce/2020/000036.htmlMailing List, Release Notes, Vendor Advisory
- https://www.debian.org/security/2021/dsa-4841Third Party Advisory
- https://www.schedmd.com/news.php?id=236Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00035.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00063.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00011.htmlMailing List, Third Party Advisory
- https://lists.schedmd.com/pipermail/slurm-announce/2020/000036.htmlMailing List, Release Notes, Vendor Advisory
- https://www.debian.org/security/2021/dsa-4841Third Party Advisory
- https://www.schedmd.com/news.php?id=236Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-12693?
How severe is CVE-2020-12693?
How do I fix CVE-2020-12693?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-12687An issue was discovered in Serpico before 1.3.3. The /admin/…6.5
- CVE-2020-12689An issue was discovered in OpenStack Keystone before 15.0.1,…8.8
- CVE-2020-1269An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-12690An issue was discovered in OpenStack Keystone before 15.0.1,…8.8
- CVE-2020-12691An issue was discovered in OpenStack Keystone before 15.0.1,…8.8
- CVE-2020-12692An issue was discovered in OpenStack Keystone before 15.0.1,…5.4
- CVE-2020-12695The Open Connectivity Foundation UPnP specification before 2…7.5
- CVE-2020-12696The iframe plugin before 4.5 for WordPress does not sanitize…6.1
- CVE-2020-12697The direct_mail extension through 5.2.3 for TYPO3 allows Den…5.3
- CVE-2020-12698The direct_mail extension through 5.2.3 for TYPO3 has Broken…4.3
- CVE-2020-12699The direct_mail extension through 5.2.3 for TYPO3 has an Ope…6.1
- CVE-2020-1270An elevation of privilege vulnerability exists in the way th…7.8
Are you affected by CVE-2020-12693?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
