NA

CVE-2020-36770

Published: 15/01/2024 Updated: 22/01/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

pkg_postinst in the Gentoo ebuild for Slurm up to and including 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by the slurm user to become the owner of root-owned files.

Vulnerable Product Search on Vulmon Subscribe to Product

gentoo ebuild for slurm