Impact
The vulnerability is a broken access control flaw where an attacker can send a crafted HTTPS POST request that sets a session variable used for authorization. When the optional Job Performance (SUPReMM) module is enabled, the attacker can override the intended restrictions and access other users' compute job efficiency metrics. This gives the attacker the ability to read confidential HPC usage statistics, potentially exposing sensitive performance data.
Affected Systems
OpenXDMoD deployments from the ubccr vendor prior to version 11.0.3 that include the optional Job Performance module are affected.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. No EPSS score is available, and the vulnerability has not been reported as exploited in the wild or listed in CISA KEV. The attack vector is an HTTPS POST request that manipulates a session variable; no special privileges or internal access are required beyond the ability to access the application endpoint. The risk is therefore moderate, mainly due to potential unauthorized disclosure of performance metrics.
OpenCVE Enrichment