VYPR
Vendor

Pacemaker\/corosync Configuration System Project

Products
4
CVEs
6
Across products
6
Status
Private

Products

4

Recent CVEs

6
  • CVE-2022-1049HigMar 25, 2022
    risk 0.57cvss 8.8epss 0.02

    A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.

  • CVE-2020-25654HigNov 24, 2020
    risk 0.47cvss 7.2epss 0.02

    An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the…

  • CVE-2010-2496MedOct 18, 2021
    risk 0.36cvss 5.5epss 0.00

    stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3…

  • CVE-2011-5271MedNov 12, 2019
    risk 0.36cvss 5.5epss 0.00

    Pacemaker before 1.1.6 configure script creates temporary files insecurely

  • CVE-2015-5190Sep 3, 2015
    risk 0.00cvss epss 0.03

    The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.

  • CVE-2015-5189Sep 3, 2015
    risk 0.00cvss epss 0.01

    Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.