Pacemaker\/corosync Configuration System Project
Products
4- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1049 | Hig | 0.57 | 8.8 | 0.02 | Mar 25, 2022 | A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login. | ||
| CVE-2020-25654 | Hig | 0.47 | 7.2 | 0.02 | Nov 24, 2020 | An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the… | ||
| CVE-2010-2496 | Med | 0.36 | 5.5 | 0.00 | Oct 18, 2021 | stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3… | ||
| CVE-2011-5271 | Med | 0.36 | 5.5 | 0.00 | Nov 12, 2019 | Pacemaker before 1.1.6 configure script creates temporary files insecurely | ||
| CVE-2015-5190 | 0.00 | — | 0.03 | Sep 3, 2015 | The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL. | |||
| CVE-2015-5189 | 0.00 | — | 0.01 | Sep 3, 2015 | Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated. |
- risk 0.57cvss 8.8epss 0.02
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.
- risk 0.47cvss 7.2epss 0.02
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the…
- risk 0.36cvss 5.5epss 0.00
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3…
- risk 0.36cvss 5.5epss 0.00
Pacemaker before 1.1.6 configure script creates temporary files insecurely
- CVE-2015-5190Sep 3, 2015risk 0.00cvss —epss 0.03
The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.
- CVE-2015-5189Sep 3, 2015risk 0.00cvss —epss 0.01
Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.