CVE-2015-1867
published 2015-08-12CVE-2015-1867: Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.00%
85.9th percentile
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clusterlabs | pacemaker | <= 1.1.12 | — |
| debian | pacemaker | — | — |
| redhat | enterprise_linux_high_availability | — | — |
| redhat | enterprise_linux_high_availability | — | — |
| redhat | enterprise_linux_resilient_storage | — | — |
| redhat | enterprise_linux_resilient_storage | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pacemaker: acl read-only access allow role assignment
vendor_redhat·2015-03-31·CVSS 7.5
CVE-2015-1867 [HIGH] CWE-863 pacemaker: acl read-only access allow role assignment
pacemaker: acl read-only access allow role assignment
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
A flaw was found in the way pacemaker, a cluster resource manager, evaluated added nodes in certain situations. A user with read-only access could potentially assign any other existing roles to themselves and then add privileges to other users as well.
Debian
CVE-2015-1867: pacemaker - Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows rem...
vendor_debian·2015·CVSS 7.5
CVE-2015-1867 [HIGH] CVE-2015-1867: pacemaker - Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows rem...
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-95mv-cmj7-gfh7: Pacemaker before 1
ghsa_unreviewed·2022-05-17
CVE-2015-1867 [HIGH] GHSA-95mv-cmj7-gfh7: Pacemaker before 1
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1867 pacemaker: acl read-only access allow role assignment [fedora-all]
bugzilla·2015-07-02·CVSS 7.5
CVE-2015-1867 [HIGH] CVE-2015-1867 pacemaker: acl read-only access allow role assignment [fedora-all]
CVE-2015-1867 pacemaker: acl read-only access allow role assignment [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2015-1867 pacemaker: acl read-only access allow role assignment
bugzilla·2015-04-13·CVSS 7.5
CVE-2015-1867 [HIGH] CVE-2015-1867 pacemaker: acl read-only access allow role assignment
CVE-2015-1867 pacemaker: acl read-only access allow role assignment
Franck Grosjean of Red Hat reports:
Description of problem:
acl definitions are not enforced and could be bypassed by a user without write access to the cib
Version-Release number of selected component (if applicable):
RedHat Enterprise Linux 6.6
pcs --version = 0.9.123
pacemakerd --version = Pacemaker 1.1.11
How reproducible:
a user with a read-only role can assign any other existing roles to himself and then gain any kind of access from any role (rw access to the cib if this kind of role exist).
Steps to Reproduce:
1. create a role read-only
pcs acl role create read-only description="Read only access" read xpath /cib
2. create a role admin
pcs acl role create admin description="Admin access" write xpath /cib
3. crea
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170610.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169671.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169995.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1424.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2383.htmlhttp://www.securityfocus.com/bid/74231https://bugzilla.redhat.com/show_bug.cgi?id=1211370https://github.com/ClusterLabs/pacemaker/commit/84ac07chttps://security.gentoo.org/glsa/201710-08http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170610.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169671.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-October/169995.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1424.htmlhttp://rhn.redhat.com/errata/RHSA-2015-2383.htmlhttp://www.securityfocus.com/bid/74231https://bugzilla.redhat.com/show_bug.cgi?id=1211370https://github.com/ClusterLabs/pacemaker/commit/84ac07chttps://security.gentoo.org/glsa/201710-08
2015-08-12
Published