CVE-2020-25654

Description

An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.

Risk Information

Base Score
7.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.086

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM MQ 9.1Windows
Multiple Vulnerabilities are affected in IBM MQ 9.2Windows
Cluster resource manager (USN-4623-1) pacemaker_2.0.3-3ubuntu4.1_amd64.debLinux
Cluster resource manager (USN-4623-1) pacemaker_2.0.4-2ubuntu3.1_amd64.debLinux
Cluster resource manager (USN-4623-1) pacemaker_1.1.14-2ubuntu1.9_i386.debLinux
Cluster resource manager (USN-4623-1) pacemaker_1.1.14-2ubuntu1.9_amd64.debLinux
Cluster resource manager (USN-4623-1) pacemaker_1.1.18-0ubuntu1.3_i386.debLinux
Cluster resource manager (USN-4623-1) pacemaker_1.1.18-0ubuntu1.3_amd64.debLinux
pacemaker security update(DSA-4791-1) pacemaker_2.0.1-5+deb10u1_i386.debLinux
pacemaker security update(DSA-4791-1) pacemaker_2.0.1-5+deb10u1_amd64.debLinux
(RHSA-2020:5487) pacemaker security update pacemaker-cluster-libs-2.0.4-6.el8_3.1.i686.rpmLinux
(RHSA-2020:5487) pacemaker security update pacemaker-cluster-libs-2.0.4-6.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5487) pacemaker security update pacemaker-debugsource-2.0.4-6.el8_3.1.i686.rpmLinux
(RHSA-2020:5487) pacemaker security update pacemaker-debugsource-2.0.4-6.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5487) pacemaker security update pacemaker-libs-2.0.4-6.el8_3.1.i686.rpmLinux
(RHSA-2020:5487) pacemaker security update pacemaker-libs-2.0.4-6.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5487) pacemaker security update pacemaker-schemas-2.0.4-6.el8_3.1.noarch.rpmLinux
Pacemaker-cluster-libs update (ELSA-2020-5487) pacemaker-cluster-libs-2.0.4-6.el8_3.1.i686.rpmLinux
Pacemaker-cluster-libs update (ELSA-2020-5487) pacemaker-cluster-libs-2.0.4-6.el8_3.1.x86_64.rpmLinux
Pacemaker-libs update (ELSA-2020-5487) pacemaker-libs-2.0.4-6.el8_3.1.i686.rpmLinux
Pacemaker-libs update (ELSA-2020-5487) pacemaker-libs-2.0.4-6.el8_3.1.x86_64.rpmLinux
Pacemaker-schemas update (ELSA-2020-5487) pacemaker-schemas-2.0.4-6.el8_3.1.noarch.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-cli-debuginfo-2.0.4-6.el8_3.1.i686.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-cli-debuginfo-2.0.4-6.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-cluster-libs-debuginfo-2.0.4-6.el8_3.1.i686.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-cluster-libs-debuginfo-2.0.4-6.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-debuginfo-2.0.4-6.el8_3.1.i686.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-debuginfo-2.0.4-6.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-libs-debuginfo-2.0.4-6.el8_3.1.i686.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-libs-debuginfo-2.0.4-6.el8_3.1.x86_64.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-remote-debuginfo-2.0.4-6.el8_3.1.i686.rpmLinux
(RHSA-2020:5487)Moderate: security update pacemaker-remote-debuginfo-2.0.4-6.el8_3.1.x86_64.rpmLinux
Pacemaker update (ELSA-2020-5453) pacemaker-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
Pacemaker-cli update (ELSA-2020-5453) pacemaker-cli-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
Pacemaker-cluster-libs update (ELSA-2020-5453) pacemaker-cluster-libs-1.1.23-1.0.1.el7_9.1.i686.rpmLinux
Pacemaker-cluster-libs update (ELSA-2020-5453) pacemaker-cluster-libs-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
Pacemaker-cts update (ELSA-2020-5453) pacemaker-cts-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
Pacemaker-doc update (ELSA-2020-5453) pacemaker-doc-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
Pacemaker-libs update (ELSA-2020-5453) pacemaker-libs-1.1.23-1.0.1.el7_9.1.i686.rpmLinux
Pacemaker-libs update (ELSA-2020-5453) pacemaker-libs-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
Pacemaker-libs-devel update (ELSA-2020-5453) pacemaker-libs-devel-1.1.23-1.0.1.el7_9.1.i686.rpmLinux
Pacemaker-libs-devel update (ELSA-2020-5453) pacemaker-libs-devel-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
Pacemaker-nagios-plugins-metadata update (ELSA-2020-5453) pacemaker-nagios-plugins-metadata-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
Pacemaker-remote update (ELSA-2020-5453) pacemaker-remote-1.1.23-1.0.1.el7_9.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-1.1.23-1.amzn2.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-cli-1.1.23-1.amzn2.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-cts-1.1.23-1.amzn2.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-doc-1.1.23-1.amzn2.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-libs-1.1.23-1.amzn2.1.i686.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-libs-1.1.23-1.amzn2.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-remote-1.1.23-1.amzn2.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-libs-devel-1.1.23-1.amzn2.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-cluster-libs-1.1.23-1.amzn2.1.i686.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-cluster-libs-1.1.23-1.amzn2.1.x86_64.rpmLinux
pacemaker Security Update (ALAS-2021-1583) pacemaker-nagios-plugins-metadata-1.1.23-1.amzn2.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234