HIGH
An issue was discovered in ClusterLabs crmsh through 4.2.1
Published Jan 12, 2021
7.8
HIGHCVSS 3.1
EPSS 0.68%
Description
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
Affected products
No data.
Configuration 1
- ≤ 4.2.1
Configuration 2
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.openwall.com/lists/oss-security/2021/01/12/3 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1179999 x_refsource_MISCIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3345 Advisory
- https://github.com/ClusterLabs/crmsh/blob/a403aa15f3ea575adfe5e43bf2a31c9f9094fcda/crmsh/history.py#L476 x_refsource_MISCPatchThird Party Advisory
- https://github.com/ClusterLabs/crmsh/releases x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/advisories/GHSA-99xx-83jm-h24m Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00021.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-35459
- https://www.openwall.com/lists/oss-security/2021/01/12/3 x_refsource_CONFIRMExploitMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2021/01/12/3 | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| https://bugzilla.suse.com/show_bug.cgi?id=1179999 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3345 | Advisory | |
| https://github.com/ClusterLabs/crmsh/blob/a403aa15f3ea575adfe5e43bf2a31c9f9094fcda/crmsh/history.py#L476 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/ClusterLabs/crmsh/releases | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/advisories/GHSA-99xx-83jm-h24m | Advisory | |
| https://lists.debian.org/debian-lts-announce/2021/01/msg00021.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-35459 | ||
| https://www.openwall.com/lists/oss-security/2021/01/12/3 | x_refsource_CONFIRMExploitMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 12, 2021
Updated Aug 4, 2024
Reserved Dec 14, 2020
Link CVE-2020-35459
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-3345 GHSA-99XX-83JM-H24M Assigner mitre
Published Jan 12, 2021
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2022-3345