Back

HIGH

pcs: obtaining an authentication token for hacluster user could lead to privilege escalation

Published Sep 6, 2022

Description

A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to have complete control over the cluster managed by PCS.

Affected products

Remediation

Red Hat statement

The bug was introduced in PCS version 0.10.5 upstream by this bugzilla. https://bugzilla.redhat.com/show_bug.cgi?id=1783106

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 6, 2022
Updated Aug 3, 2024
Reserved Aug 9, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 1, 2022
ENISA EUVD
Assigner redhat
Published Sep 6, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-34977