CVE-2020-35459

EUVD-2022-3345
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
clusterlabscrmsh
𝑥
≤ 4.2.1
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
crmsh
bookworm
4.4.1-1+deb12u1
fixed
bullseye
4.2.1-2
fixed
sid
4.6.0-3
fixed
trixie
4.6.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
crmsh
bionic
needed
focal
Fixed 4.2.0-2ubuntu1.1
released
groovy
ignored
hirsute
ignored
impish
ignored
jammy
Fixed 4.2.1-2
released
kinetic
ignored
lunar
ignored
mantic
Fixed 4.2.1-2
released
noble
Fixed 4.2.1-2
released
trusty
not-affected
xenial
needed