Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-25654
Description:An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.
Test IDs: 1.3.6.1.4.1.25623.1.0.883308   1.3.6.1.4.1.25623.1.0.892519   1.3.6.1.4.1.25623.1.0.704791   1.3.6.1.4.1.25623.1.0.853551   1.3.6.1.4.1.25623.1.0.853555   1.3.6.1.4.1.25623.1.0.844702   1.3.6.1.4.1.25623.1.0.878659   1.3.6.1.4.1.25623.1.1.10.2020.0409   1.3.6.1.4.1.25623.1.0.878664  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-25654
https://security.gentoo.org/glsa/202309-09
https://bugzilla.redhat.com/show_bug.cgi?id=1888191
https://bugzilla.redhat.com/show_bug.cgi?id=1888191
https://lists.clusterlabs.org/pipermail/users/2020-October/027840.html
https://lists.clusterlabs.org/pipermail/users/2020-October/027840.html
https://seclists.org/oss-sec/2020/q4/83
https://seclists.org/oss-sec/2020/q4/83
https://lists.debian.org/debian-lts-announce/2021/01/msg00007.html




© 1998-2025 E-Soft Inc. All rights reserved.