CVE-2015-1867
12.08.2015, 14:59
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | enterprise_linux_high_availability | 6.0 |
| redhat | enterprise_linux_high_availability | 7.0 |
| redhat | enterprise_linux_resilient_storage | 6.0 |
| redhat | enterprise_linux_resilient_storage | 7.0 |
| clusterlabs | pacemaker | 𝑥 ≤ 1.1.12 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| pacemaker |
| ||||
| pacemaker-cli |
| ||||
| pacemaker-cluster-libs |
| ||||
| pacemaker-cts |
| ||||
| pacemaker-doc |
| ||||
| pacemaker-libs |
| ||||
| pacemaker-libs-devel |
| ||||
| pacemaker-nagios-plugins-metadata |
| ||||
| pacemaker-remote |
|
Common Weakness Enumeration
References