Improper access control in Pacemaker - CVE-2020-25654
Published: November 24, 2020 / Updated: December 22, 2020
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in pacemaker. A local account on the cluster and in the haclient group can use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.
Affected software
Debian Linux
CentOS
Red Hat Enterprise Linux Resilient Storage for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Fedora
pacemaker (Ubuntu package)
pacemaker (Red Hat package)
pacemaker (Debian package)
pacemaker
pacemaker-schemas
pacemaker-cts
pacemaker-nagios-plugins-metadata
pacemaker-doc
pacemaker-debuginfo
pacemaker-remote
pacemaker-libs
pacemaker-cli
pacemaker-cluster-libs
pacemaker-libs-devel
pacemaker-debugsource
How to mitigate CVE-2020-25654
pacemaker (Ubuntu package) - addressed in versions 1.1.14-2ubuntu1.9, 1.1.18-0ubuntu1.3, 2.0.3-3ubuntu4.1, 2.0.4-2ubuntu3.1
pacemaker (Red Hat package) - addressed in versions 1.1.23-1.el7_9.1, 2.0.3-5.el8_2.3, 2.0.4-6.el8_3.1
pacemaker (Debian package) - update to 2.0.1-5+deb10u1
pacemaker - update to 2.0.3-3
pacemaker-schemas - update to 2.0.3-3
pacemaker-cts - update to 2.0.3-3
pacemaker-nagios-plugins-metadata - update to 2.0.3-3
pacemaker-doc - update to 2.0.3-3
pacemaker-debuginfo - update to 2.0.3-3
pacemaker-remote - update to 2.0.3-3
pacemaker-libs - update to 2.0.3-3
pacemaker-cli - update to 2.0.3-3
pacemaker-cluster-libs - update to 2.0.3-3
pacemaker-libs-devel - update to 2.0.3-3
pacemaker-debugsource - update to 2.0.3-3
pacemaker - addressed in versions 2.0.5-0.5.rc2.fc32, 2.0.5-0.5.rc2.fc33, 2.0.5-0.7.rc3.fc32, 2.0.5-0.7.rc3.fc33
External References
Related Security Bulletins
- Security restrictions bypass in ClusterLabs Pacemaker
- Red Hat Enterprise Linux 7 update for pacemaker
- Red Hat Enterprise Linux 8 update for pacemaker
- CentOS 7 update for pacemaker
- Debian update for pacemaker
- Red Hat Enterprise Linux 8.2 Extended Update Support update for pacemaker
- openEuler 20.03 LTS SP3 update for pacemaker
- openEuler 20.03 LTS SP1 update for pacemaker
- Ubuntu update for pacemaker
- Fedora 33 update for pacemaker
- Fedora 32 update for pacemaker
- Fedora 32 update for pacemaker
- Fedora 33 update for pacemaker