VulnerabilityModified
CVE-2020-35459
Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
HIGH 7.8EPSS 0.68%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentially allowing escalation of privileges.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- clusterlabs/crmsh · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2021/01/12/3Mailing List, Patch, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1179999Issue Tracking, Third Party Advisory
- https://github.com/ClusterLabs/crmsh/blob/a403aa15f3ea575adfe5e43bf2a31c9f9094fcda/crmsh/history.py#L476Patch, Third Party Advisory
- https://github.com/ClusterLabs/crmsh/releasesRelease Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00021.htmlMailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/01/12/3Exploit, Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/01/12/3Mailing List, Patch, Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1179999Issue Tracking, Third Party Advisory
- https://github.com/ClusterLabs/crmsh/blob/a403aa15f3ea575adfe5e43bf2a31c9f9094fcda/crmsh/history.py#L476Patch, Third Party Advisory
- https://github.com/ClusterLabs/crmsh/releasesRelease Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/01/msg00021.htmlMailing List, Third Party Advisory
- https://www.openwall.com/lists/oss-security/2021/01/12/3Exploit, Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.