File _patchinfo of Package patchinfo.19753
<patchinfo incident="19753">
<issue tracker="cve" id="2021-31215"/>
<issue tracker="bnc" id="1180700">[slurm] Provides/Conflicts of package libnss_slurm* are wrong</issue>
<issue tracker="bnc" id="1186024">[Slurm] VUL-0: CVE-2021-31215: slurm_20_11,slurm,slurmlibs,slurm_20_02,slurm_18_08: SchedMD Slurm allows remote code execution as SlurmUser</issue>
<issue tracker="bnc" id="1185603">[slurmrestd] Add missing YAML support</issue>
<packager>eeich</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for slurm_20_11</summary>
<description>This update for slurm_20_11 fixes the following issues:
- Udpate to 20.11.7:
- CVE-2021-31215: remote code execution as SlurmUser because of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling (bsc#1186024)
- Ship REST API version and auth plugins with slurmrestd.
- Add YAML support for REST API to build (bsc#1185603).
- Fix Provides:/Conflicts: for libnss_slurm (bsc#1180700).
</description>
</patchinfo>