VYPR

fence-agents

by Clusterlabs

CVEs (2)

  • CVE-2014-0104MedJan 2, 2020
    risk 0.38cvss 5.9epss 0.01

    In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

  • CVE-2019-10153MedJul 30, 2019
    risk 0.00cvss 5.0epss 0.02

    A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise…