CVE-2015-1867

Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_high_availability:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_high_availability:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_resilient_storage:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_resilient_storage:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:clusterlabs:pacemaker:*:*:*:*:*:*:*:*

History

12 Feb 2023, 23:15

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:1424', 'name': 'https://access.redhat.com/errata/RHSA-2015:1424', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2015-1867', 'name': 'https://access.redhat.com/security/cve/CVE-2015-1867', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:2383', 'name': 'https://access.redhat.com/errata/RHSA-2015:2383', 'tags': [], 'refsource': 'MISC'}
Summary A flaw was found in the way pacemaker, a cluster resource manager, evaluated added nodes in certain situations. A user with read-only access could potentially assign any other existing roles to themselves and then add privileges to other users as well. Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

02 Feb 2023, 16:16

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2015:1424 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2015-1867 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:2383 -
Summary Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command. A flaw was found in the way pacemaker, a cluster resource manager, evaluated added nodes in certain situations. A user with read-only access could potentially assign any other existing roles to themselves and then add privileges to other users as well.

Information

Published : 2015-08-12 14:59

Updated : 2023-12-10 11:46


NVD link : CVE-2015-1867

Mitre link : CVE-2015-1867

CVE.ORG link : CVE-2015-1867


JSON object : View

Products Affected

redhat

  • enterprise_linux_high_availability
  • enterprise_linux_resilient_storage

clusterlabs

  • pacemaker
CWE
CWE-264

Permissions, Privileges, and Access Controls