pcs: obtaining an authentication token for hacluster user could lead to privilege escalation
Published Sep 6, 2022
8.4
HIGHCVSS 3.1
EPSS 0.32%
Description
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to have complete control over the cluster managed by PCS.
Affected products
- Vendor n/a Product ClusterLabs/pcs Defaultn/a
- Version Affects v0.10.5 and later including all 0.11.x.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | ClusterLabs/pcs | n/a |
|
Configuration 1
- ≥ 0.10.5 · ≤ 0.11.3
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 8
pcs-0:0.10.12-6.el8_6.2
Fixed · RHSA-2022:6314
Red Hat Enterprise Linux 8.2 Extended Update Support
pcs-0:0.10.4-6.el8_2.3
Fixed · RHSA-2022:6341
Red Hat Enterprise Linux 8.4 Extended Update Support
pcs-0:0.10.8-1.el8_4.2
Fixed · RHSA-2022:6312
Red Hat Enterprise Linux 9
pcs-0:0.11.1-10.el9_0.2
Fixed · RHSA-2022:6313
Red Hat Enterprise Linux 7
pcs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | pcs-0:0.10.12-6.el8_6.2 | Fixed | RHSA-2022:6314 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | pcs-0:0.10.4-6.el8_2.3 | Fixed | RHSA-2022:6341 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | pcs-0:0.10.8-1.el8_4.2 | Fixed | RHSA-2022:6312 |
| Red Hat Enterprise Linux 9 | pcs-0:0.11.1-10.el9_0.2 | Fixed | RHSA-2022:6313 |
| Red Hat Enterprise Linux 7 | pcs | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The bug was introduced in PCS version 0.10.5 upstream by this bugzilla. https://bugzilla.redhat.com/show_bug.cgi?id=1783106
References (7)
- https://access.redhat.com/security/cve/CVE-2022-2735 x_refsource_MISCThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2116815 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34977 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2735
- https://www.cve.org/CVERecord?id=CVE-2022-2735
- https://www.debian.org/security/2022/dsa-5226 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.openwall.com/lists/oss-security/2022/09/01/4 x_refsource_MISCMailing ListRelease NotesThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2735 | x_refsource_MISCThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2116815 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34977 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2735 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2735 | ||
| https://www.debian.org/security/2022/dsa-5226 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.openwall.com/lists/oss-security/2022/09/01/4 | x_refsource_MISCMailing ListRelease NotesThird Party Advisory |
Change history (0)
No recorded changes yet.