Search CVE reports


Toggle filters

1 – 10 of 11 results


CVE-2026-10649

Medium priority
Needs evaluation

(A flaw was found in Pacemaker. An unauthenticated remote attacker can ...)

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2010-2496

Medium priority
Not affected

stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in...

2 affected packages

cluster-glue, pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cluster-glue Not affected Not affected Not affected
pacemaker Not affected Not affected Not affected
Show less packages

CVE-2020-25654

Medium priority
Fixed

An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented...

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker Fixed Fixed
Show less packages

CVE-2011-5271

Low priority
Ignored

Pacemaker before 1.1.6 configure script creates temporary files insecurely

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker
Show less packages

CVE-2019-3885

Low priority
Fixed

A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker Fixed
Show less packages

CVE-2018-16878

Medium priority
Fixed

A flaw was found in pacemaker up to and including version 2.0.1. An insufficient verification inflicted preference of uncontrolled processes can lead to DoS

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker Fixed
Show less packages

CVE-2018-16877

Medium priority
Fixed

A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege...

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker Fixed
Show less packages

CVE-2016-7797

Medium priority

Some fixes available 1 of 2

Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker
Show less packages

CVE-2016-7035

Medium priority

Some fixes available 2 of 4

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local...

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker
Show less packages

CVE-2015-1867

Medium priority
Not affected

Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

1 affected package

pacemaker

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pacemaker
Show less packages