{"id":"CVE-2023-49938","details":"An issue was discovered in SchedMD Slurm 22.05.x and 23.02.x. There is Incorrect Access Control: an attacker can modified their extended group list that is used with the sbcast subsystem, and open files with an unauthorized set of extended groups. The fixed versions are 22.05.11 and 23.02.7.","modified":"2026-08-12T03:51:28.139821398Z","published":"2023-12-14T00:00:00Z","related":["SUSE-SU-2024:0278-1","SUSE-SU-2024:0279-1","SUSE-SU-2024:0280-1","SUSE-SU-2024:0283-1","SUSE-SU-2024:0284-1","SUSE-SU-2024:0286-1","SUSE-SU-2024:0287-1","SUSE-SU-2024:0288-1","SUSE-SU-2024:0289-1","SUSE-SU-2024:0309-1","SUSE-SU-2024:0310-1","SUSE-SU-2024:0311-1","SUSE-SU-2024:0312-1","SUSE-SU-2024:0313-1","SUSE-SU-2024:0314-1","SUSE-SU-2024:0315-1","openSUSE-SU-2024:13559-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49938.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63FEDDYEE2WK7FHWBHKON3OZVQI56WSQ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AYQS3LFGC4HE4WCW4L3NAA2I6FRIWMNO/"},{"type":"WEB","url":"https://lists.schedmd.com/pipermail/slurm-announce/2023/000103.html"},{"type":"WEB","url":"https://www.schedmd.com/security-archive.php"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49938.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63FEDDYEE2WK7FHWBHKON3OZVQI56WSQ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AYQS3LFGC4HE4WCW4L3NAA2I6FRIWMNO/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49938"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/schedmd/slurm","events":[{"introduced":"04d4ec01c9aeccc9e352c721985b036b4d8126b9"},{"fixed":"608e2f502ffe0decc5564cb51525ddfd4cc59efd"},{"introduced":"ee331a70786953b901d079ff93ff9de9ac47d1cd"},{"fixed":"7d4666c7d539fb056399b898f1b82f2e2bb20bb1"}],"database_specific":{"extracted_events":[{"introduced":"22.05.0"},{"fixed":"22.05.11"},{"introduced":"23.02.0"},{"fixed":"23.02.7"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:*"}}],"versions":["slurm-22-05-10-1","slurm-22-05-9-1","slurm-22-05-8-1","slurm-22-05-7-1","slurm-22-05-6-1","slurm-22-05-5-1","slurm-22-05-4-1","slurm-22-05-3-1","slurm-22-05-2-1","slurm-22-05-1-1","slurm-22-05-0-1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49938.json"}}],"schema_version":"1.9.0"}