AWSGHSA-x775-rxcq-38x8
Security vulnerability in a third party software, Slurm < 20.11.9 and 21.08.8
CriticalPublished May 16, 2022
AWS ParallelCluster versions **3.1.4** and **2.11.7** were released in order to update the Slurm software to versions 21.08.8 and 20.11.9, respectively. This change was made in response to SchedMD’s release of these versions on 2022-05-04, to provide fixes related to the following CVEs: CVE-2022-29500, CVE-2022-29501, and CVE-2022-29502.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Slurm Product | < 20.11.9 | 20.11.9 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 102022 | Privilege Escalation Vector in CloudWatch Agent for Windows | High7.1 | 1.247355 |
| Sep 272022 | Issue with configuring session ticket names in s2n-tls | Medium | v1.3.23 |
| Sep 272022 | Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake | Low | <v1.3.23 |
| Aug 92022 | Partial Path Traversal in aws-cpp-sdk-transfer | Medium | v1.9.318 |
| Jul 152022 | Partial Path Traversal in com.amazonaws:aws-java-sdk-s3 | High7.9 | 1.12.261 |
| May 52022 | Potential denial of service when sending version negotiation or close packets | Medium | v1.1.1 |