CVE-2020-35459
Summary
| CVE | CVE-2020-35459 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-12 15:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| oss-security - Security issues in hawk2 and crmsh |
CONFIRM |
www.openwall.com |
Exploit, Mailing List, Third Party Advisory |
| Releases · ClusterLabs/crmsh · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| oss-security - Security issues in hawk2 and crmsh |
MLIST |
www.openwall.com |
Mailing List, Patch, Third Party Advisory |
| Bug 1179999 – VUL-0: CVE-2020-35459: crmsh: Root privilege escalation via hawk_invoke and crmsh |
MISC |
bugzilla.suse.com |
Issue Tracking, Third Party Advisory |
| [SECURITY] [DLA 2533-1] crmsh security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| crmsh/history.py at a403aa15f3ea575adfe5e43bf2a31c9f9094fcda · ClusterLabs/crmsh · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 200227 Ubuntu Security Notification for CRM shell Vulnerability (USN-6711-1)
- 750296 OpenSUSE Security Update for hawk2 (openSUSE-SU-2021:0473-1)
- 750318 OpenSUSE Security Update for crmsh (openSUSE-SU-2021:0410-1)
- 750423 OpenSUSE Security Update for crmsh (openSUSE-SU-2021:0073-1)
- 750437 OpenSUSE Security Update for crmsh (openSUSE-SU-2021:0055-1)
- 750878 OpenSUSE Security Update for crmsh (openSUSE-SU-2021:2435-1)
- 750890 OpenSUSE Security Update for crmsh (openSUSE-SU-2021:1087-1)