Skip to content

Security vulnerability in a third party software, Slurm < 20.02.07 and 20.11.7

High
mauri-melato published GHSA-qxh2-h6cj-g562 May 19, 2021

Package

Slurm (Slurm)

Affected versions

before 20.02.7 and 20.03.x through 20.11.x before 20.11.7

Patched versions

20.02.07 and 20.11.7

Description

AWS ParallelCluster version 2.10.4 was released in order to update the Slurm package to version 20.02.7. This change was made in response to SchedMD’s release of Slurm versions 20.02.7 and 20.11.7 on 2021-05-12 to provide bug fixes as well as a security fix related to the use of Slurm Prolog and Epilog scripts in multi-user environments (https://groups.google.com/g/slurm-users/c/0kPOtrvHrkE?pli=1).

Severity

High

CVE ID

CVE-2021-31215

Weaknesses

No CWEs