CVE-2018-1086
published 2018-04-12CVE-2018-1086: pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.65%
74.1th percentile
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clusterlabs | pacemaker_command_line_interface | — | — |
| clusterlabs | pacemaker_command_line_interface | — | — |
| clusterlabs | pcs | >= 0 < 0.9.164-1 | 0.9.164-1 |
| clusterlabs | pcs | >= 0 < 0.9.164-1 | 0.9.164-1 |
| clusterlabs | pcs | >= 0 < 0.9.164-1 | 0.9.164-1 |
| clusterlabs | pcs | >= 0 < 0.9.164-1 | 0.9.164-1 |
| clusterlabs | pcs | >= 0 < 0.9.149-1ubuntu1.1+esm1 | 0.9.149-1ubuntu1.1+esm1 |
| clusterlabs | pcs | >= 0 < 0.10.4-3ubuntu0.1~esm1 | 0.10.4-3ubuntu0.1~esm1 |
| clusterlabs | pcs | >= 0 < 0.10.11-2ubuntu3+esm1 | 0.10.11-2ubuntu3+esm1 |
| debian | debian_linux | — | — |
| debian | pcs | < pcs 0.9.164-1 (bookworm) | pcs 0.9.164-1 (bookworm) |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | pcs | — | — |
| redhat | pcs | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu6.1MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
pcs vulnerabilities
vendor_ubuntu·2025-07-02·CVSS 6.1
CVE-2022-2735 [MEDIUM] pcs vulnerabilities
Title: pcs vulnerabilities
Summary: Several security issues were fixed in pcs.
Cedric Buissart discovered that pcs did not correctly handle certain
parameters. An attacker could possibly use this issue to leak sensitive
information or elevate their privileges. This issue only affected
Ubuntu 16.04 LTS. (CVE-2018-1086)
Ondrej Mular discovered that pcs did not correctly handle Unix socket
permissions. An attacker could possibly use this issue to elevate their
privileges. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2735)
It was discovered that pcs did not correctly handle PAM authentication.
An attacker could possibly use this issue to bypass authentication
mechanisms. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-1049)
It was discovered that pcs did
Red Hat
pcs: Debug parameter removal bypass, allowing information disclosure
vendor_redhat·2018-04-09·CVSS 4.3
CVE-2018-1086 [MEDIUM] CWE-20 pcs: Debug parameter removal bypass, allowing information disclosure
pcs: Debug parameter removal bypass, allowing information disclosure
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.
It was found that the REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.
Package: pcs (Red Hat Enterprise Linux 8) - Not affected
Package: pcs (Red Hat Storage 3) - Not affected
Debian
CVE-2018-1086: pcs - pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal ...
vendor_debian·2018·CVSS 4.3
CVE-2018-1086 [MEDIUM] CVE-2018-1086: pcs - pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal ...
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.
Scope: local
bookworm: resolved (fixed in 0.9.164-1)
bullseye: resolved (fixed in 0.9.164-1)
forky: resolved (fixed in 0.9.164-1)
sid: resolved (fixed in 0.9.164-1)
trixie: resolved (fixed in 0.9.164-1)
OSV
pcs vulnerabilities
osv·2025-07-02·CVSS 6.1
CVE-2018-1086 [MEDIUM] pcs vulnerabilities
pcs vulnerabilities
Cedric Buissart discovered that pcs did not correctly handle certain
parameters. An attacker could possibly use this issue to leak sensitive
information or elevate their privileges. This issue only affected
Ubuntu 16.04 LTS. (CVE-2018-1086)
Ondrej Mular discovered that pcs did not correctly handle Unix socket
permissions. An attacker could possibly use this issue to elevate their
privileges. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2735)
It was discovered that pcs did not correctly handle PAM authentication.
An attacker could possibly use this issue to bypass authentication
mechanisms. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-1049)
It was discovered that pcs did not correctly handle the validation of
Node names. An attack
GHSA
GHSA-p9pc-vgv7-x9j9: pcs before versions 0
ghsa_unreviewed·2022-05-13
CVE-2018-1086 [HIGH] CWE-200 GHSA-p9pc-vgv7-x9j9: pcs before versions 0
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.
OSV
CVE-2018-1086: pcs before versions 0
osv·2018-04-12·CVSS 7.5
CVE-2018-1086 [HIGH] CVE-2018-1086: pcs before versions 0
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure [fedora-all]
bugzilla·2018-04-09·CVSS 4.3
CVE-2018-1086 [MEDIUM] CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure [fedora-all]
CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1557366,1565090
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that users r
Bugzilla
CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure
bugzilla·2018-03-16·CVSS 4.3
CVE-2018-1086 [MEDIUM] CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure
CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure
To prevent some information disclosure, pcsd actively removes '--debug' from command requested over the REST interface, but this can be bypassed:
----88----
The information gained could then be used to gain higher privileges.
Discussion:
Acknowledgments:
Name: Cedric Buissart (Red Hat)
---
Created pcs tracking bugs for this issue:
Affects: fedora-all [bug 1565090]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2018:1060 https://access.redhat.com/errata/RHSA-2018:1060
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2018:1927 https://access.redhat.com/errata/RHSA-2018:1927
https://access.redhat.com/errata/RHSA-2018:1060https://access.redhat.com/errata/RHSA-2018:1927https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1086https://www.debian.org/security/2018/dsa-4169https://access.redhat.com/errata/RHSA-2018:1060https://access.redhat.com/errata/RHSA-2018:1927https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1086https://www.debian.org/security/2018/dsa-4169
2018-04-12
Published