Clusterlabs Pacemaker vulnerabilities

10 known vulnerabilities affecting clusterlabs/pacemaker.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2010-2496MEDIUMCVSS 5.5fixed in 1.1.32021-10-18
CVE-2010-2496 [MEDIUM] CWE-287 CVE-2010-2496: stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possi stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3 and newer.
nvd
CVE-2020-25654HIGHCVSS 7.2fixed in 1.1.23≥ 2.0.0, < 2.0.3+1 more2020-11-24
CVE-2020-25654 [HIGH] CWE-284 CVE-2020-25654: An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.
nvd
CVE-2011-5271MEDIUMCVSS 5.5fixed in 1.1.62019-11-12
CVE-2011-5271 [MEDIUM] CWE-59 CVE-2011-5271: Pacemaker before 1.1.6 configure script creates temporary files insecurely Pacemaker before 1.1.6 configure script creates temporary files insecurely
nvd
CVE-2018-16877HIGHCVSS 7.8≤ 2.0.0vaffects up to and including Pacemaker-2.0.02019-04-18
CVE-2018-16877 [HIGH] CWE-287 CVE-2018-16877: A flaw was found in the way pacemaker's client-server authentication was implemented in versions up A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.
cvelistv5nvd
CVE-2019-3885HIGHCVSS 7.5≤ 2.0.1vaffects up to and including version 2.0.12019-04-18
CVE-2019-3885 [LOW] CWE-416 CVE-2019-3885: A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
cvelistv5nvd
CVE-2018-16878MEDIUMCVSS 5.5≤ 2.0.1vaffects up to and including version 2.0.12019-04-18
CVE-2018-16878 [MEDIUM] CWE-400 CVE-2018-16878: A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflic A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS
cvelistv5nvd
CVE-2016-7035HIGHCVSS 7.8≤ 1.1.16v1.1.162018-09-10
CVE-2016-7035 [HIGH] CWE-285 CVE-2016-7035: An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.
cvelistv5nvd
CVE-2016-7797HIGHCVSS 7.5≤ 1.1.142017-03-24
CVE-2016-7797 [HIGH] CWE-254 CVE-2016-7797: Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
nvd
CVE-2015-1867HIGHCVSS 7.5≤ 1.1.122015-08-12
CVE-2015-1867 [HIGH] CWE-264 CVE-2015-1867: Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
nvd
CVE-2013-0281MEDIUMCVSS 4.3v1.1.102013-11-23
CVE-2013-0281 [MEDIUM] CWE-399 CVE-2013-0281: Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).
nvd