rpm package
suse/hawk2&distro=SUSE Linux Enterprise High Availability Extension 12 SP5
pkg:rpm/suse/hawk2&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-25314 | — | < 2.6.3+git.1614685906.812c31e9-3.30.1 | 2.6.3+git.1614685906.812c31e9-3.30.1 | Apr 14, 2021 | A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue a | ||
| CVE-2020-35459 | — | < 2.6.3+git.1614685906.812c31e9-3.30.1 | 2.6.3+git.1614685906.812c31e9-3.30.1 | Jan 12, 2021 | An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges. | ||
| CVE-2020-35458 | — | < 2.4.0+git.1607523195.05cd3222-3.21.1 | 2.4.0+git.1607523195.05cd3222-3.21.1 | Jan 12, 2021 | An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser. |
- CVE-2021-25314Apr 14, 2021affected < 2.6.3+git.1614685906.812c31e9-3.30.1fixed 2.6.3+git.1614685906.812c31e9-3.30.1
A Creation of Temporary File With Insecure Permissions vulnerability in hawk2 of SUSE Linux Enterprise High Availability 12-SP3, SUSE Linux Enterprise High Availability 12-SP5, SUSE Linux Enterprise High Availability 15-SP2 allows local attackers to escalate to root. This issue a
- CVE-2020-35459Jan 12, 2021affected < 2.6.3+git.1614685906.812c31e9-3.30.1fixed 2.6.3+git.1614685906.812c31e9-3.30.1
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
- CVE-2020-35458Jan 12, 2021affected < 2.4.0+git.1607523195.05cd3222-3.21.1fixed 2.4.0+git.1607523195.05cd3222-3.21.1
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.