Записи ClusterLabs
27 опубликованных записей вендора clusterlabs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-20 Improper Input Validation1
- CWE-269 Improper Privilege Management1
- CWE-276 Incorrect Default Permissions1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-35458Эксплойта нет | An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x.clusterlabs · hawk · CWE-78 | Критическая9,8 | — | 5,3 % | 12 янв. 2021 г. |
39Наблюдать | CVE-2023-39976Эксплойта нет | log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.clusterlabs · libqb · CWE-120 | Критическая9,8 | — | 1,2 % | 8 авг. 2023 г. |
39Наблюдать | CVE-2023-2319Эксплойта нет | It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to includclusterlabs · pcs | Критическая9,8 | — | 1,0 % | 17 мая 2023 г. |
36Наблюдать | CVE-2022-1049Эксплойта нет | A flaw was found in the Pacemaker configuration tool (pcs).clusterlabs · pcs · CWE-287 | Высокая8,8 | — | 2,0 % | 25 мар. 2022 г. |
35Наблюдать | CVE-2016-0720Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.clusterlabs · pcs · CWE-352 | Высокая8,8 | — | 1,4 % | 21 апр. 2017 г. |
35Наблюдать | CVE-2021-3020Эксплойта нет | An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15.clusterlabs · hawk · CWE-269 | Высокая8,8 | — | 1,2 % | 25 авг. 2022 г. |
33Наблюдать | CVE-2016-0721Эксплойта нет | Session fixation vulnerability in pcsd in pcs before 0.9.157.clusterlabs · pcs · CWE-384 | Высокая8,1 | — | 2,3 % | 21 апр. 2017 г. |
31Наблюдать | CVE-2016-7797Эксплойта нет | Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an clusterlabs · pacemaker · CWE-254 | Высокая7,5 | — | 3,3 % | 24 мар. 2017 г. |
31Наблюдать | CVE-2015-1867Эксплойта нет | Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.redhat · enterprise linux high availability · CWE-264 | Высокая7,5 | — | 3,0 % | 12 авг. 2015 г. |
31Наблюдать | CVE-2019-3885Эксплойта нет | A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaclusterlabs · pacemaker · CWE-416 | Высокая7,5 | — | 2,0 % | 18 апр. 2019 г. |
31Наблюдать | CVE-2018-1086Эксплойта нет | pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass.clusterlabs · pacemaker command line interface · CWE-20 | Высокая7,5 | — | 1,9 % | 12 апр. 2018 г. |
31Наблюдать | CVE-2020-35459Эксплойта нет | An issue was discovered in ClusterLabs crmsh through 4.2.1.clusterlabs · crmsh · CWE-78 | Высокая7,8 | — | 0,7 % | 12 янв. 2021 г. |
31Наблюдать | CVE-2016-7035Эксплойта нет | An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface.clusterlabs · pacemaker · CWE-285 | Высокая7,8 | — | 0,4 % | 10 сент. 2018 г. |
31Наблюдать | CVE-2018-16877Эксплойта нет | A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0.clusterlabs · pacemaker · CWE-287 | Высокая7,8 | — | 0,4 % | 18 апр. 2019 г. |
31Наблюдать | CVE-2022-2735Эксплойта нет | A vulnerability was found in the PCS project.clusterlabs · pcs · CWE-276 | Высокая7,8 | — | 0,3 % | 6 сент. 2022 г. |
29Наблюдать | CVE-2020-25654Эксплойта нет | An ACL bypass flaw was found in pacemaker.clusterlabs · pacemaker · CWE-284 | Высокая7,2 | — | 1,9 % | 24 нояб. 2020 г. |
28Наблюдать | CVE-2019-12779Эксплойта нет | libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/sclusterlabs · libqb · CWE-59 | Высокая7,1 | — | 0,7 % | 7 июн. 2019 г. |
26Наблюдать | CVE-2022-2553Эксплойта нет | The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node.clusterlabs · booth · CWE-287 | Средняя6,5 | — | 1,3 % | 28 июл. 2022 г. |
26Наблюдать | CVE-2018-1079Эксплойта нет | pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call.clusterlabs · pacemaker command line interface · CWE-552 | Средняя6,5 | — | 1,1 % | 12 апр. 2018 г. |
24Наблюдать | CVE-2017-2661Эксплойта нет | ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field wclusterlabs · pcs · CWE-79 | Средняя6,1 | — | 1,2 % | 12 мар. 2018 г. |
23Наблюдать | CVE-2014-0104Эксплойта нет | In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-iclusterlabs · fence-agents · CWE-295 | Средняя5,9 | — | 0,8 % | 2 янв. 2020 г. |
23Наблюдать | CVE-2024-3049Эксплойта нет | Booth: specially crafted hash can lead to invalid hmac being accepted by booth serverclusterlabs · booth · CWE-345 | Средняя5,9 | — | 0,5 % | 6 июн. 2024 г. |
22Наблюдать | CVE-2011-5271Эксплойта нет | Pacemaker before 1.1.6 configure script creates temporary files insecurelyclusterlabs · pacemaker · CWE-59 | Средняя5,5 | — | 0,5 % | 12 нояб. 2019 г. |
22Наблюдать | CVE-2018-16878Эксплойта нет | A flaw was found in pacemaker up to and including version 2.0.1.clusterlabs · pacemaker · CWE-400 | Средняя5,5 | — | 0,4 % | 18 апр. 2019 г. |
22Наблюдать | CVE-2010-2496Эксплойта нет | stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access tclusterlabs · cluster glue · CWE-287 | Средняя5,5 | — | 0,2 % | 18 окт. 2021 г. |
- CVE-2020-3545841В плане
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %clusterlabs · hawk12 янв. 2021 г.
- CVE-2023-3997639Наблюдать
log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %clusterlabs · libqb8 авг. 2023 г.
- CVE-2023-231939Наблюдать
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to includ
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %clusterlabs · pcs17 мая 2023 г.
- CVE-2022-104936Наблюдать
A flaw was found in the Pacemaker configuration tool (pcs).
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %clusterlabs · pcs25 мар. 2022 г.
- CVE-2016-072035Наблюдать
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %clusterlabs · pcs21 апр. 2017 г.
- CVE-2021-302035Наблюдать
An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %clusterlabs · hawk25 авг. 2022 г.
- CVE-2016-072133Наблюдать
Session fixation vulnerability in pcsd in pcs before 0.9.157.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %clusterlabs · pcs21 апр. 2017 г.
- CVE-2016-779731Наблюдать
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %clusterlabs · pacemaker24 мар. 2017 г.
- CVE-2015-186731Наблюдать
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %redhat · enterprise linux high availability12 авг. 2015 г.
- CVE-2019-388531Наблюдать
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be lea
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %clusterlabs · pacemaker18 апр. 2019 г.
- CVE-2018-108631Наблюдать
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %clusterlabs · pacemaker command line interface12 апр. 2018 г.
- CVE-2020-3545931Наблюдать
An issue was discovered in ClusterLabs crmsh through 4.2.1.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %clusterlabs · crmsh12 янв. 2021 г.
- CVE-2016-703531Наблюдать
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %clusterlabs · pacemaker10 сент. 2018 г.
- CVE-2018-1687731Наблюдать
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %clusterlabs · pacemaker18 апр. 2019 г.
- CVE-2022-273531Наблюдать
A vulnerability was found in the PCS project.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %clusterlabs · pcs6 сент. 2022 г.
- CVE-2020-2565429Наблюдать
An ACL bypass flaw was found in pacemaker.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %clusterlabs · pacemaker24 нояб. 2020 г.
- CVE-2019-1277928Наблюдать
libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/s
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %clusterlabs · libqb7 июн. 2019 г.
- CVE-2022-255326Наблюдать
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %clusterlabs · booth28 июл. 2022 г.
- CVE-2018-107926Наблюдать
pcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %clusterlabs · pacemaker command line interface12 апр. 2018 г.
- CVE-2017-266124Наблюдать
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field w
СредняяCVSS 6,1Эксплойта нетEPSS 1 %clusterlabs · pcs12 мар. 2018 г.
- CVE-2014-010423Наблюдать
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-i
СредняяCVSS 5,9Эксплойта нетEPSS 1 %clusterlabs · fence-agents2 янв. 2020 г.
- CVE-2024-304923Наблюдать
Booth: specially crafted hash can lead to invalid hmac being accepted by booth server
СредняяCVSS 5,9Эксплойта нетEPSS 1 %clusterlabs · booth6 июн. 2024 г.
- CVE-2011-527122Наблюдать
Pacemaker before 1.1.6 configure script creates temporary files insecurely
СредняяCVSS 5,5Эксплойта нетEPSS 0 %clusterlabs · pacemaker12 нояб. 2019 г.
- CVE-2018-1687822Наблюдать
A flaw was found in pacemaker up to and including version 2.0.1.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %clusterlabs · pacemaker18 апр. 2019 г.
- CVE-2010-249622Наблюдать
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access t
СредняяCVSS 5,5Эксплойта нетEPSS 0 %clusterlabs · cluster glue18 окт. 2021 г.