(3.9.0-3.13.0) Privilege escalation on Slurm accounting caused by CVE-2025-43904
- Dominant language
- Python
- Stars
- 888
- Forks
- 314
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 43
Description
### The issue
Slurm versions 23.11 and 24.05 are affected by CVE-2025-43904. When Slurm accounting is enabled on the cluster, this vulnerability allows a Coordinator user to promote another user to Administrator.
### Affected ParallelCluster versions, OSes and schedulers
All ParallelCluster versions from 3.9.0 to 3.13.0 on all OSes, when Slurm accounting is enabled and Coordinator users are configured.
### Mitigation
You can find a detailed explanation and the mitigation of the problem [here](https://github.com/aws/aws-parallelcluster/wiki/(3.9.0%E2%80%903.13.0)-Privilege-escalation-on-Slurm-accounting-caused-by-CVE%E2%80%902025%E2%80%9043904).
Contributor guide
Research direction
The issue is actionable through the linked wiki mitigation; begin there and review the stated ParallelCluster versions, operating systems, and Slurm-accounting/Coordinator conditions. No repository file, test, or code change is named, so the completion criteria must be clarified before implementation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100