AWSGHSA-qxh2-h6cj-g562
Security vulnerability in a third party software, Slurm < 20.02.07 and 20.11.7
HighCVE-2021-31215 · Published May 19, 2021 · updated Dec 8, 2021
AWS ParallelCluster version 2.10.4 was released in order to update the Slurm package to version 20.02.7. This change was made in response to SchedMD’s release of Slurm versions 20.02.7 and 20.11.7 on 2021-05-12 to provide bug fixes as well as a security fix related to the use of Slurm Prolog and Epilog scripts in multi-user environments (https://groups.google.com/g/slurm-users/c/0kPOtrvHrkE?pli=1).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Slurm Product | < 20.02.07and20.11.7 | 20.02.07and20.11.7 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 162022 | Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8 | Critical | 20.11.9 |
| May 52022 | Potential denial of service when sending version negotiation or close packets | Medium | v1.1.1 |
| Dec 142020 | Allocated memory not freed when session ticket is used | Low | v0.10.23 |
| Oct 122020 | Predictable IV in CBC-mode composite cipher suites | Low | v0.10.19 |
| Oct 122020 | Online Certificate Stapling Protocol (OCSP) Revocation check bypass | Low | v0.10.19 |
| Oct 122020 | Server denial-of-service via crafted handshake message | Low | v0.10.19 |