Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Enterprise_linux_high_availability | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_high_availability | Redhat | 7.0 (including) | 7.0 (including) |
Enterprise_linux_resilient_storage | Redhat | 6.0 (including) | 6.0 (including) |
Enterprise_linux_resilient_storage | Redhat | 7.0 (including) | 7.0 (including) |
Red Hat Enterprise Linux 6 | RedHat | pacemaker-0:1.1.12-8.el6 | * |
Red Hat Enterprise Linux 7 | RedHat | pacemaker-0:1.1.13-10.el7 | * |
Pacemaker | Ubuntu | devel | * |