Wind River Support Network

HomeDefectsLIN10-9179
Fixed

LIN10-9179 : Security Advisory - cluster-glue - CVE-2010-2496

Created: Oct 18, 2021    Updated: May 13, 2022
Resolved Date: Oct 25, 2021
Found In Version: 10.17.41.1
Fix Version: 10.17.41.24
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3 and newer.

CREATE(Triage):(User=admin) CVE-2010-2496 (https://nvd.nist.gov/vuln/detail/CVE-2010-2496)

CVEs


Live chat
Online