|Number of vulnerabilities||1|
Red Hat Enterprise Linux Resilient Storage for x86_64
Operating systems & Components / Operating system
pacemaker (Red Hat package)
Operating systems & Components / Operating system package or component
|Vendor||Red Hat Inc.|
This security bulletin contains one low risk vulnerability.
Exploit availability: NoDescription
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in pacemaker. A local account on the cluster and in the haclient group can use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.Mitigation
Install updates from vendor's website.
Red Hat Enterprise Linux Resilient Storage for x86_64: 7
pacemaker (Red Hat package): before 1.1.23-1.el7_9.1
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?