7.2
CVSSv2

CVE-2020-35459

Published: 12/01/2021 Updated: 21/07/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in ClusterLabs crmsh up to and including 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clusterlabs crmsh

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #985376 CVE-2020-35459 Package: crmsh; Maintainer for crmsh is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Source for crmsh is src:crmsh (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 16 Mar 2021 20:00:02 UTC Severity: grave Tags: ...