CVE-2022-2735
Summary
| CVE | CVE-2022-2735 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-06 18:15:00 UTC |
| Updated | 2024-01-25 21:29:00 UTC |
| Description | A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to have complete control over the cluster managed by PCS. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| 2116815 – (CVE-2022-2735) CVE-2022-2735 pcs: obtaining an authentication token for hacluster user could lead to privilege escalation |
MISC |
bugzilla.redhat.com |
|
| Debian -- Security Information -- DSA-5226-1 pcs |
DEBIAN |
www.debian.org |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| oss-security - ClusterLabs/PCS: [CVE-2022-2735] Obtaining an authentication token
for hacluster user leads to privilege escalation. |
MISC |
www.openwall.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160073 Oracle Enterprise Linux Security Update for pcs (ELSA-2022-9754)
- 160074 Oracle Enterprise Linux Security Update for pcs (ELSA-2022-9753)
- 180998 Debian Security Update for pcs (DSA 5226-1)
- 182524 Debian Security Update for pcs (CVE-2022-2735)
- 240646 Red Hat Update for pcs (RHSA-2022:6313)
- 240647 Red Hat Update for pcs (RHSA-2022:6314)
- 240648 Red Hat Update for pcs (RHSA-2022:6312)
- 240649 Red Hat Update for pcs (RHSA-2022:6341)
- 940652 AlmaLinux Security Update for pcs (ALSA-2022:6314)
- 940661 AlmaLinux Security Update for pcs (ALSA-2022:6313)
- 960168 Rocky Linux Security Update for pcs (RLSA-2022:6314)
- 960495 Rocky Linux Security Update for pcs (RLSA-2022:6313)