CRITICAL
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x
Published Jan 12, 2021
9.8
CRITICALCVSS 3.1
EPSS 5.33%
Description
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.
Affected products
No data.
OR
- 2.2.0-12
- 2.3.0-12
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://www.openwall.com/lists/oss-security/2021/01/12/3 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1179998 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/ClusterLabs/hawk/releases x_refsource_MISCRelease NotesThird Party Advisory
- https://www.openwall.com/lists/oss-security/2021/01/12/3 x_refsource_CONFIRMMailing ListPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2021/01/12/3 | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| https://bugzilla.suse.com/show_bug.cgi?id=1179998 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://github.com/ClusterLabs/hawk/releases | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://www.openwall.com/lists/oss-security/2021/01/12/3 | x_refsource_CONFIRMMailing ListPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 12, 2021
Updated Aug 4, 2024
Reserved Dec 14, 2020
Link CVE-2020-35458
CISA Vulnrichment
Updated n/a