Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wmv-gcg2-v47h

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.

EPSS

Процентиль: 33%
0.00395
Низкий

7.8 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.

CVSS3: 8.8
redhat
почти 10 лет назад

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.

CVSS3: 8.8
nvd
почти 8 лет назад

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.

CVSS3: 8.8
debian
почти 8 лет назад

An authorization flaw was found in Pacemaker before 1.1.16, where it d ...

suse-cvrf
больше 9 лет назад

Security update for pacemaker

EPSS

Процентиль: 33%
0.00395
Низкий

7.8 High

CVSS3

Дефекты

CWE-285