threat
engine
.sh
Back
·
··:··
Home
/
Product
/
clusterlabs pacemaker
Product
clusterlabs pacemaker
10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2010-2496
< 1.1.3
stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gai
5.5
MEDIUM
CVE-2020-25654
< 1.1.23
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use I
7.2
HIGH
CVE-2011-5271
< 1.1.6
Pacemaker before 1.1.6 configure script creates temporary files insecurely
5.5
MEDIUM
CVE-2019-3885
<= 2.0.1
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information
3.3
LOW
CVE-2018-16878
<= 2.0.1
A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled
5.5
MEDIUM
CVE-2018-16877
<= 2.0.0
A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A loca
7.8
HIGH
CVE-2016-7035
<= 1.1.16
An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an
8.8
HIGH
CVE-2016-7797
<= 1.1.14
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnectio
7.5
HIGH
CVE-2015-1867
<= 1.1.12
Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl
CVE-2013-0281
all versions
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the d
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin