← Back

Clusterlabs

clusterlabs

27 CVEs • 9 products

Products (9)

Click to collapse
Toggle
Pacemaker
pacemaker
Pcs
pcs
Libqb
libqb
Fence Agents
fence-agents
Hawk
hawk
Booth
booth
Crmsh
crmsh
Cluster Glue
cluster_glue

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Clusterlabs
DebianRedhat
3Debian Linux
Enterprise Linux Server EusPacemaker Command Line Interface
Nov 21, 2024
Apr 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensi...Show more
pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.Show less
1Clusterlabs
1Pcs
Nov 21, 2024
Mar 12, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.
3Clusterlabs
FedoraprojectRedhat
3Enterprise Linux
FedoraPcs
May 13, 2026
Apr 21, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Session fixation vulnerability in pcsd in pcs before 0.9.157.
3Clusterlabs
FedoraprojectRedhat
3Enterprise Linux
FedoraPcs
May 13, 2026
Apr 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
5Clusterlabs
OpensuseOpensuse Project+2 more
7Enterprise Linux High Availability
Enterprise Linux Resilient StorageLeap+4 more
May 13, 2026
Mar 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
2Clusterlabs
Redhat
3Enterprise Linux High Availability
Enterprise Linux Resilient StoragePacemaker
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
2Clusterlabs
Redhat
2Enterprise Linux
Pacemaker
Apr 29, 2026
Nov 23, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a d...Show more
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).Show less