CVE-2020-25654
Summary
| CVE | CVE-2020-25654 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-24 20:15:00 UTC |
| Updated | 2023-09-29 11:15:00 UTC |
| Description | An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Clusterlabs | Pacemaker | All | All | All | All |
| Application | Clusterlabs | Pacemaker | 2.0.5 | rc1 | All | All |
| Application | Clusterlabs | Pacemaker | All | All | All | All |
| Application | Clusterlabs | Pacemaker | 2.0.5 | rc1 | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 2519-1] pacemaker security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| oss-sec: CVE-2020-25654 pacemaker: ACL restrictions bypass | MISC | seclists.org | Mailing List, Third Party Advisory |
| 1888191 – (CVE-2020-25654) CVE-2020-25654 pacemaker: ACL restrictions bypass | MISC | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| [ClusterLabs] FYI: Pacemaker vulnerability CVE-2020-25654 | MISC | lists.clusterlabs.org | Mailing List, Vendor Advisory |
| Pacemaker: Multiple Vulnerabilities (GLSA 202309-09) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159659 Oracle Enterprise Linux Security Update for pacemaker (ELSA-2020-5453)
- 375682 IBM MQ Control List Bypass Vulnerability(6464787)
- 377400 Alibaba Cloud Linux Security Update for pacemaker (ALINUX3-SA-2021:0004)
- 710753 Gentoo Linux Pacemaker Multiple Vulnerabilities (GLSA 202309-09)
- 940322 AlmaLinux Security Update for pacemaker (ALSA-2020:5487)