Critical severity9.8NVD Advisory· Published Jan 12, 2021· Updated Jun 17, 2026
CVE-2020-35458
CVE-2020-35458
Description
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:clusterlabs:hawk:2.2.0-12:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:clusterlabs:hawk:2.2.0-12:*:*:*:*:*:*:*
- cpe:2.3:a:clusterlabs:hawk:2.3.0-12:*:*:*:*:*:*:*
- (no CPE)range: 2.x through 2.3.0-x
- ClusterLabs/Hawkdescription
- osv-coords9 versionspkg:rpm/opensuse/hawk2&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/hawk2&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/hawk2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/hawk2&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP3pkg:rpm/suse/hawk2&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4pkg:rpm/suse/hawk2&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5pkg:rpm/suse/hawk2&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015pkg:rpm/suse/hawk2&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP1pkg:rpm/suse/hawk2&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP2
< 2.3.0+git.1603969748.10468582-lp151.2.18.1+ 8 more
- (no CPE)range: < 2.3.0+git.1603969748.10468582-lp151.2.18.1
- (no CPE)range: < 2.3.0+git.1603969748.10468582-lp152.2.9.1
- (no CPE)range: < 2.6.4+git.1682509819.1ff135ea-1.1
- (no CPE)range: < 2.4.0+git.1607523195.05cd3222-2.33.1
- (no CPE)range: < 2.4.0+git.1607523195.05cd3222-3.21.1
- (no CPE)range: < 2.4.0+git.1607523195.05cd3222-3.21.1
- (no CPE)range: < 2.3.0+git.1603969748.10468582-3.18.1
- (no CPE)range: < 2.3.0+git.1603969748.10468582-3.18.1
- (no CPE)range: < 2.3.0+git.1603969748.10468582-3.18.1
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2021/01/12/3nvdMailing ListPatchThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2021/01/12/3nvdMailing ListPatchThird Party Advisory
- github.com/ClusterLabs/hawk/releasesnvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.