Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
| Software | From | Fixed in |
|---|---|---|
| schedmd / slurm | 17.11.0-rc1 | 17.11.0-rc1.x |
| schedmd / slurm | 17.02.0 | 17.2.09 |
| schedmd / slurm | - | 16.05.11 |