CVE-2020-35459
published 2021-01-12CVE-2020-35459: An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.68%
48.7th percentile
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clusterlabs | crmsh | <= 4.2.1 | — |
| clusterlabs | crmsh | >= 0 < 4.2.1-2 | 4.2.1-2 |
| clusterlabs | crmsh | >= 0 < 4.2.1-2 | 4.2.1-2 |
| clusterlabs | crmsh | >= 0 < 4.2.1-2 | 4.2.1-2 |
| clusterlabs | crmsh | >= 0 < 4.2.1-2 | 4.2.1-2 |
| clusterlabs | crmsh | 0 – 4.2.1 | — |
| debian | crmsh | < crmsh 4.2.1-2 (bookworm) | crmsh 4.2.1-2 (bookworm) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ClusterLabs crmsh vulnerable to shell code injection
osv·2022-05-24
CVE-2020-35459 [HIGH] ClusterLabs crmsh vulnerable to shell code injection
ClusterLabs crmsh vulnerable to shell code injection
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call `crm history` (when `crm` is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
GHSA
ClusterLabs crmsh vulnerable to shell code injection
ghsa·2022-05-24
CVE-2020-35459 [HIGH] CWE-269 ClusterLabs crmsh vulnerable to shell code injection
ClusterLabs crmsh vulnerable to shell code injection
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call `crm history` (when `crm` is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
OSV
CVE-2020-35459: An issue was discovered in ClusterLabs crmsh through 4
osv·2021-01-12·CVSS 7.8
CVE-2020-35459 [HIGH] CVE-2020-35459: An issue was discovered in ClusterLabs crmsh through 4
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
Ubuntu
CRM shell vulnerability
vendor_ubuntu·2024-03-25
CVE-2020-35459 CRM shell vulnerability
Title: CRM shell vulnerability
Summary: CRM shell could be made to execute arbitrary code if it received
a specially crafted input.
Vincent Berg discovered that CRM shell incorrectly handled certain commands.
An local attacker could possibly use this issue to execute arbitrary code
via shell code injection to the crm history commandline.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-35459: crmsh - An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able...
vendor_debian·2020·CVSS 7.8
CVE-2020-35459 [HIGH] CVE-2020-35459: crmsh - An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able...
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
Scope: local
bookworm: resolved (fixed in 4.2.1-2)
bullseye: resolved (fixed in 4.2.1-2)
forky: resolved (fixed in 4.2.1-2)
sid: resolved (fixed in 4.2.1-2)
trixie: resolved (fixed in 4.2.1-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/01/12/3https://bugzilla.suse.com/show_bug.cgi?id=1179999https://github.com/ClusterLabs/crmsh/blob/a403aa15f3ea575adfe5e43bf2a31c9f9094fcda/crmsh/history.py#L476https://github.com/ClusterLabs/crmsh/releaseshttps://lists.debian.org/debian-lts-announce/2021/01/msg00021.htmlhttps://www.openwall.com/lists/oss-security/2021/01/12/3http://www.openwall.com/lists/oss-security/2021/01/12/3https://bugzilla.suse.com/show_bug.cgi?id=1179999https://github.com/ClusterLabs/crmsh/blob/a403aa15f3ea575adfe5e43bf2a31c9f9094fcda/crmsh/history.py#L476https://github.com/ClusterLabs/crmsh/releaseshttps://lists.debian.org/debian-lts-announce/2021/01/msg00021.htmlhttps://www.openwall.com/lists/oss-security/2021/01/12/3
2021-01-12
Published