← Back

CVE-2010-2496

nvd nist
Published: Oct 18, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3 and newer.

Affected (2)

2 products
Cluster Glue
Pacemaker
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.6
Before 1.1.3

References (2)

Source: secalert@redhat.com
Issue TrackingMailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListPatchThird Party Advisory

Timeline

No history available yet.