CVE-2020-35459

An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
VendorProductVersion
clusterlabscrmsh
𝑥
≤ 4.2.1
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
crmsh
bullseye
4.2.1-2
fixed
bookworm
4.4.1-1+deb12u1
fixed
sid
4.6.0-3
fixed
trixie
4.6.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
crmsh
noble
Fixed 4.2.1-2
released
mantic
Fixed 4.2.1-2
released
lunar
ignored
kinetic
ignored
jammy
Fixed 4.2.1-2
released
impish
ignored
hirsute
ignored
groovy
ignored
focal
Fixed 4.2.0-2ubuntu1.1
released
bionic
needed
xenial
needed
trusty
not-affected