Skip to main content

Vendor archive

clusterlabs CVEs

Beta · best-effort

27 CVEs tagged to vendor clusterlabs3 Critical, 13 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2024-3049

Published Jun 6, 2024

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth ser…

CVSS 5.9 · Medium

CVE-2023-39976

Published Aug 8, 2023

log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2735

Published Sep 6, 2022

A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege esca…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3020

Published Aug 26, 2022

An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setui…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1049

Published Mar 25, 2022

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authenticatio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35459

Published Jan 12, 2021

An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35458

Published Jan 12, 2021

An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0104

Published Jan 2, 2020

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL ser…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12779

Published Jun 7, 2019

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16877

Published Apr 18, 2019

A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it wi…

CVSS 7.8 · High

CVE-2017-2661

Published Mar 12, 2018

ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding exis…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2