Known Vulnerabilities for Pacemaker by Clusterlabs
Listed below are 10 of the newest known vulnerabilities associated with "Pacemaker" by "Clusterlabs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-25654 json | An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could ... | 7.2 - HIGH | 2020-11-24 | 2023-09-29 |
| CVE-2019-3885 json | A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive inform... | 7.5 - HIGH | 2019-04-18 | 2023-11-07 |
| CVE-2018-16878 json | A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontr... | 5.5 - MEDIUM | 2019-04-18 | 2023-11-07 |
| CVE-2018-16877 json | A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A... | 7.8 - HIGH | 2019-04-18 | 2023-11-07 |
| CVE-2016-7797 json | Not Provided | 2017-03-24 | 2025-04-20 | |
| CVE-2016-7035 json | An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker wi... | 7.8 - HIGH | 2018-09-10 | 2023-11-07 |
| CVE-2015-1867 json | Not Provided | 2015-08-12 | 2026-05-06 | |
| CVE-2013-0281 json | Not Provided | 2013-11-23 | 2026-04-29 | |
| CVE-2011-5271 json | Pacemaker before 1.1.6 configure script creates temporary files insecurely | 5.5 - MEDIUM | 2019-11-12 | 2019-11-14 |
| CVE-2010-2496 json | stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers t... | 5.5 - MEDIUM | 2021-10-18 | 2021-10-21 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Clusterlabs | Pacemaker | 2.0.5 | |||
| Application | Clusterlabs | Pacemaker | 2.0.5 | |||
| Application | Clusterlabs | Pacemaker | 2.0.5 | |||
| Application | Clusterlabs | Pacemaker | 2.0.5 | |||
| Application | Clusterlabs | Pacemaker | 2.0.4 | |||
| Application | Clusterlabs | Pacemaker | 2.0.4 | |||
| Application | Clusterlabs | Pacemaker | 2.0.4 | |||
| Application | Clusterlabs | Pacemaker | 2.0.4 | |||
| Application | Clusterlabs | Pacemaker | 2.0.3 | |||
| Application | Clusterlabs | Pacemaker | 2.0.3 | |||
| Application | Clusterlabs | Pacemaker | 2.0.3 | |||
| Application | Clusterlabs | Pacemaker | 2.0.3 | |||
| Application | Clusterlabs | Pacemaker | 2.0.2 | |||
| Application | Clusterlabs | Pacemaker | 2.0.2 | |||
| Application | Clusterlabs | Pacemaker | 2.0.2 | |||
| Application | Clusterlabs | Pacemaker | 2.0.2 | |||
| Application | Clusterlabs | Pacemaker | 2.0.1 | |||
| Application | Clusterlabs | Pacemaker | 2.0.1 | |||
| Application | Clusterlabs | Pacemaker | 2.0.1 | |||
| Application | Clusterlabs | Pacemaker | 2.0.1 |