Clusterlabs / Pacemaker
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2010-2496 | cluster-glue: passes the stonith parameters via the commandline which could result in password leaks | HIGH | 7.8 | Oct 18, 2021 |
| CVE-2020-25654 | pacemaker: ACL restrictions bypass | HIGH | 7.2 | Nov 24, 2020 |
| CVE-2011-5271 | Pacemaker before 1.1.6 configure script creates temporary files insecurely | MEDIUM | 5.5 | Nov 12, 2019 |
| CVE-2019-3885 | pacemaker: Information disclosure through use-after-free | HIGH | 7.5 | Apr 18, 2019 |
| CVE-2018-16878 | pacemaker: Insufficient verification inflicted preference of uncontrolled processes can lead to DoS | MEDIUM | 5.5 | Apr 18, 2019 |
| CVE-2018-16877 | pacemaker: Insufficient local IPC client-server authentication on the client's side can lead to local privesc | HIGH | 7.8 | Apr 18, 2019 |
| CVE-2016-7035 | pacemaker: Privilege escalation due to improper guarding of IPC communication | HIGH | 8.8 | Sep 10, 2018 |
| CVE-2016-7797 | pacemaker: pacemaker remote nodes vulnerable to hijacking, resulting in a DoS attack | HIGH | 8.6 | Mar 24, 2017 |
| CVE-2015-1867 | pacemaker: acl read-only access allow role assignment | HIGH | 7.5 | Aug 12, 2015 |
| CVE-2013-0281 | pacemaker: remote DoS when CIB management is enabled caused by use of blocking sockets | MEDIUM | 4.3 | Nov 23, 2013 |
Showing 1 to 10 of 10 CVEs