CVE-2010-2496
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3 and newer.
Affected (2)
Products: Clusterlabs: Cluster Glue, Pacemaker
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.6 | |
| Before 1.1.3 |
References (2)
Source: secalert@redhat.com
Issue TrackingMailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListPatchThird Party Advisory
Timeline
No history available yet.