Improper access control in Pacemaker - CVE-2020-25654

 

Improper access control in Pacemaker - CVE-2020-25654

Published: November 24, 2020 / Updated: December 22, 2020


Vulnerability identifier: #VU49118
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25654
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in pacemaker. A local account on the cluster and in the haclient group can use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.


Affected software

Pacemaker
Debian Linux
CentOS
Red Hat Enterprise Linux Resilient Storage for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Fedora
pacemaker (Ubuntu package)
pacemaker (Red Hat package)
pacemaker (Debian package)
pacemaker
pacemaker-schemas
pacemaker-cts
pacemaker-nagios-plugins-metadata
pacemaker-doc
pacemaker-debuginfo
pacemaker-remote
pacemaker-libs
pacemaker-cli
pacemaker-cluster-libs
pacemaker-libs-devel
pacemaker-debugsource

How to mitigate CVE-2020-25654

Install updates from vendor's website.

Pacemaker - addressed in versions 1.1.24, 2.0.5
pacemaker (Ubuntu package) - addressed in versions 1.1.14-2ubuntu1.9, 1.1.18-0ubuntu1.3, 2.0.3-3ubuntu4.1, 2.0.4-2ubuntu3.1
pacemaker (Red Hat package) - addressed in versions 1.1.23-1.el7_9.1, 2.0.3-5.el8_2.3, 2.0.4-6.el8_3.1
pacemaker (Debian package) - update to 2.0.1-5+deb10u1
pacemaker - update to 2.0.3-3
pacemaker-schemas - update to 2.0.3-3
pacemaker-cts - update to 2.0.3-3
pacemaker-nagios-plugins-metadata - update to 2.0.3-3
pacemaker-doc - update to 2.0.3-3
pacemaker-debuginfo - update to 2.0.3-3
pacemaker-remote - update to 2.0.3-3
pacemaker-libs - update to 2.0.3-3
pacemaker-cli - update to 2.0.3-3
pacemaker-cluster-libs - update to 2.0.3-3
pacemaker-libs-devel - update to 2.0.3-3
pacemaker-debugsource - update to 2.0.3-3
pacemaker - addressed in versions 2.0.5-0.5.rc2.fc32, 2.0.5-0.5.rc2.fc33, 2.0.5-0.7.rc3.fc32, 2.0.5-0.7.rc3.fc33

External References

Related Security Bulletins