7.5
CVSSv2

CVE-2015-1867

Published: 12/08/2015 Updated: 12/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Pacemaker prior to 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux high availability 6.0

redhat enterprise linux resilient storage 7.0

redhat enterprise linux resilient storage 6.0

redhat enterprise linux high availability 7.0

clusterlabs pacemaker

Vendor Advisories

A flaw was found in the way pacemaker, a cluster resource manager, evaluated added nodes in certain situations A user with read-only access could potentially assign any other existing roles to themselves and then add privileges to other users as well ...