#VU66985 Permissions, Privileges, and Access Controls in pcs - CVE-2022-2735
Published: September 5, 2022 / Updated: April 7, 2023
pcs
ClusterLabs
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect permissions set on a Unix socket used for internal communication between PCS daemons. A local user can obtain the authentication token for hacluster and gain control over the cluster managed by pcs.