PT-2015-5478 · Clusterlabs+3 · Pacemaker+3

Franck Grosjean

·

Published

2015-07-20

·

Updated

2023-02-12

·

CVE-2015-1867

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pacemaker versions prior to 1.1.13
Description The issue allows remote read-only users to gain privileges via an acl command due to improper evaluation of added nodes.
Recommendations For versions prior to 1.1.13, update to version 1.1.13 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1923
CESA-2015_1424
CESA-2015_2383
CVE-2015-1867
RHSA-2015:1424
RHSA-2015:2383
RHSA-2015_1424
RHSA-2015_2383

Affected Products

Alt Linux
Centos
Pacemaker
Red Hat