Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Enterprise_linux_high_availability | Redhat | 6.0 (including) | 6.0 (including) |
| Enterprise_linux_high_availability | Redhat | 7.0 (including) | 7.0 (including) |
| Enterprise_linux_resilient_storage | Redhat | 6.0 (including) | 6.0 (including) |
| Enterprise_linux_resilient_storage | Redhat | 7.0 (including) | 7.0 (including) |
| Red Hat Enterprise Linux 6 | RedHat | pacemaker-0:1.1.12-8.el6 | * |
| Red Hat Enterprise Linux 7 | RedHat | pacemaker-0:1.1.13-10.el7 | * |
| Pacemaker | Ubuntu | devel | * |