CVE-2011-2907
Publication date 15 August 2011
Last updated 24 July 2024
Ubuntu priority
Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program.
Status
Package | Ubuntu Release | Status |
---|---|---|
torque | 18.04 LTS bionic | Not in release |
16.04 LTS xenial | Ignored | |
14.04 LTS trusty | Ignored | |
Notes
ebarretto
Closing this as: Not fixable, would need an update to a release with MUNGE support, clusters typically run in locked down environments