Vulnerability Name:

CVE-2015-1867 (CCN-102207)

Assigned:2015-03-31
Published:2015-03-31
Updated:2023-02-12
Summary:Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
CVSS v3 Severity:4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.0 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P)
4.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.0 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P)
4.4 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-863
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: Cluster Labs Web site
Pacemaker

Source: MITRE
Type: CNA
CVE-2015-1867

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: oss-security Mailing List, Mon, 13 Apr 2015 13:12:45 -0600
CVE-2015-1867 pacemaker: acl read-only access allow role assignment

Source: CCN
Type: BID-74231
Pacemaker CVE-2015-1867 Security Bypass Vulnerability

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla – Bug 1211370
(CVE-2015-1867) CVE-2015-1867 pacemaker: acl read-only access allow role assignment

Source: secalert@redhat.com
Type: Issue Tracking
secalert@redhat.com

Source: XF
Type: UNKNOWN
pacemaker-cve20151867-sec-bypass(102207)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-1867

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:clusterlabs:pacemaker:1.1.11:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20151867
    V
    CVE-2015-1867
    2022-09-02
    oval:org.opensuse.security:def:6346
    P
    Security update for libEMF (Moderate) (in QA)
    2022-08-29
    oval:org.opensuse.security:def:6
    P
    apparmor-abstractions-2.13.6-1.31 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:19
    P
    btrfsmaintenance-0.4.2-1.11 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:6335
    P
    Security update for ImageMagick (Important)
    2022-05-31
    oval:org.opensuse.security:def:6324
    P
    Security update for libreoffice (Moderate)
    2022-04-04
    oval:org.opensuse.security:def:6360
    P
    Security update for cyrus-sasl (Important)
    2022-03-03
    oval:org.opensuse.security:def:6305
    P
    Security update for apache2 (Important)
    2022-01-17
    oval:org.opensuse.security:def:112752
    P
    libpacemaker-devel-1.1.15+git20161104.b6f251a-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:6292
    P
    Security update for python2-numpy (Moderate) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:6302
    P
    Security update for libmspack (Low)
    2022-01-13
    oval:org.opensuse.security:def:10443
    P
    Security update for SDL2 (Important) (in QA)
    2022-01-12
    oval:org.opensuse.security:def:6294
    P
    Security update for kubevirt, virt-api-container, virt-controller-container, virt-handler-container, virt-launcher-container, virt-operator-container (Important)
    2022-01-10
    oval:org.opensuse.security:def:9635
    P
    Security update for xorg-x11-server (Important)
    2021-12-20
    oval:org.opensuse.security:def:7297
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-12-15
    oval:org.opensuse.security:def:10381
    P
    Security update for fetchmail (Moderate)
    2021-12-14
    oval:org.opensuse.security:def:6462
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:10375
    P
    Security update for mariadb (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:10183
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:9622
    P
    Security update for aaa_base (Moderate)
    2021-12-03
    oval:org.opensuse.security:def:10368
    P
    Security update for ruby2.5 (Important)
    2021-12-01
    oval:org.opensuse.security:def:9819
    P
    Security update for poppler (Important)
    2021-12-01
    oval:org.opensuse.security:def:10367
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:7286
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:10666
    P
    Security update for the Linux Kernel (Important)
    2021-11-19
    oval:org.opensuse.security:def:10359
    P
    Security update for qemu (Important)
    2021-11-04
    oval:org.opensuse.security:def:9803
    P
    Security update for dnsmasq (Moderate)
    2021-10-27
    oval:org.opensuse.security:def:7275
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-10-12
    oval:org.opensuse.security:def:9797
    P
    Security update for apache2 (Important)
    2021-10-12
    oval:org.opensuse.security:def:106224
    P
    libpacemaker-devel-1.1.15+git20161104.b6f251a-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:9593
    P
    Security update for ffmpeg (Important)
    2021-09-23
    oval:org.opensuse.security:def:7265
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:7264
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:9789
    P
    Security update for openssl-1_0_0 (Low)
    2021-09-09
    oval:org.opensuse.security:def:6454
    P
    Security update for openssl-1_0_0 (Important)
    2021-08-24
    oval:org.opensuse.security:def:9778
    P
    Security update for openssl-1_0_0 (Important)
    2021-08-24
    oval:org.opensuse.security:def:9576
    P
    Security update for krb5 (Important)
    2021-08-20
    oval:org.opensuse.security:def:10136
    P
    Security update for libass (Important)
    2021-08-20
    oval:org.opensuse.security:def:9568
    P
    Security update for go1.15 (Moderate)
    2021-08-20
    oval:org.opensuse.security:def:67542
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:10317
    P
    Security update for libsndfile (Critical)
    2021-08-17
    oval:org.opensuse.security:def:10688
    P
    Security update for MozillaThunderbird (Important)
    2021-07-22
    oval:org.opensuse.security:def:6451
    P
    Security update for the Linux Kernel (Important)
    2021-07-21
    oval:org.opensuse.security:def:9366
    P
    Security update for curl (Moderate)
    2021-07-21
    oval:org.opensuse.security:def:7253
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:9554
    P
    Security update for nodejs10 (Important)
    2021-07-15
    oval:org.opensuse.security:def:9546
    P
    Security update for go1.15 (Important)
    2021-06-30
    oval:org.opensuse.security:def:10295
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:6473
    P
    Security update for the Linux Kernel (Important)
    2021-06-28
    oval:org.opensuse.security:def:10110
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:10292
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:6284
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:9344
    P
    Security update for MozillaFirefox (Important)
    2021-06-09
    oval:org.opensuse.security:def:10097
    P
    Security update for spice-gtk (Important)
    2021-06-09
    oval:org.opensuse.security:def:12783
    P
    libpacemaker3-1.1.16-4.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11348
    P
    libXvMC1-1.0.8-3.57 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70895
    P
    ecryptfs-utils-111-2.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:123989
    P
    libpacemaker3-1.1.19+20180928.0d2680780-1.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16039
    P
    libpacemaker-devel-1.1.15-19.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11326
    P
    java-1_7_0-openjdk-plugin-1.5.1-1.13 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12794
    P
    libpacemaker3-1.1.19+20180928.0d2680780-1.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:124560
    P
    libpacemaker-devel-1.1.19+20180928.0d2680780-1.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16283
    P
    libpacemaker-devel-1.1.16-4.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16554
    P
    libpacemaker-devel-1.1.19+20180928.0d2680780-1.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12773
    P
    libpacemaker3-1.1.15-19.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15829
    P
    libpacemaker-devel-1.1.13-10.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70782
    P
    Security update for MozillaThunderbird (Moderate)
    2021-06-04
    oval:org.opensuse.security:def:10088
    P
    Security update for avahi (Important)
    2021-06-03
    oval:org.opensuse.security:def:9703
    P
    Security update for java-11-openjdk (Important)
    2021-05-11
    oval:org.opensuse.security:def:10068
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:9493
    P
    Security update for libnettle (Important)
    2021-04-28
    oval:org.opensuse.security:def:10060
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:6443
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:9684
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:9669
    P
    Security update for ruby2.5 (Important)
    2021-03-24
    oval:org.opensuse.security:def:10675
    P
    Security update for evolution-data-server (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:9474
    P
    Security update for libass (Important)
    2021-03-24
    oval:org.opensuse.security:def:9867
    P
    Security update for nghttp2 (Important)
    2021-03-24
    oval:org.opensuse.security:def:7243
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP2) (Important)
    2021-03-17
    oval:org.opensuse.security:def:9865
    P
    Security update for openssl-1_0_0 (Moderate)
    2021-03-11
    oval:org.opensuse.security:def:10217
    P
    Security update for openldap2 (Important)
    2021-03-08
    oval:org.opensuse.security:def:9657
    P
    Security update for kernel-firmware (Important)
    2021-03-03
    oval:org.opensuse.security:def:9459
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:9854
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:10397
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:6316
    P
    Security update for ImageMagick (Moderate)
    2021-02-25
    oval:org.opensuse.security:def:9845
    P
    Security update for php7 (Important)
    2021-02-24
    oval:org.opensuse.security:def:6314
    P
    Security update for ImageMagick (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:9644
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:6313
    P
    Security update for python (Important)
    2021-02-11
    oval:org.opensuse.security:def:10198
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:9412
    P
    Security update for java-11-openjdk (Important)
    2021-02-09
    oval:org.opensuse.security:def:10599
    P
    Security update for MozillaThunderbird (Important)
    2021-01-29
    oval:org.opensuse.security:def:9336
    P
    Security update for wavpack (Moderate)
    2021-01-21
    oval:org.opensuse.security:def:10090
    P
    Security update for wavpack (Moderate)
    2021-01-21
    oval:org.opensuse.security:def:6422
    P
    Security update for the Linux Kernel (Important)
    2021-01-14
    oval:org.opensuse.security:def:6417
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:6441
    P
    Security update for openssl-1_0_0 (Important)
    2020-12-11
    oval:org.opensuse.security:def:11019
    P
    Security update for neomutt (Moderate)
    2020-12-04
    oval:org.opensuse.security:def:16862
    P
    libpacemaker-devel-1.1.21+20190809.bf34b44fa-1.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:89539
    P
    libpacemaker-devel-2.0.1+20190417.13d370ca9-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103194
    P
    libpacemaker-devel-2.0.1+20190417.13d370ca9-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:96504
    P
    libpacemaker-devel-2.0.1+20190417.13d370ca9-1.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:12805
    P
    libpacemaker3-1.1.21+20190809.bf34b44fa-1.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4026
    P
    libpacemaker-devel-1.1.21+20190809.bf34b44fa-1.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:6439
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-02
    oval:org.opensuse.security:def:6541
    P
    xscreensaver on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6626
    P
    gstreamer-0_10-plugins-base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6537
    P
    xlockmore on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6624
    P
    gstreamer on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9927
    P
    libthai-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6595
    P
    eog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10490
    P
    libcurl-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10021
    P
    xorg-x11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6392
    P
    libjpeg-turbo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10524
    P
    libnettle-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6592
    P
    elfutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10527
    P
    libpacemaker-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6604
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10624
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6551
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6637
    P
    hyper-v on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6548
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64195
    P
    libpacemaker-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6606
    P
    gd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6428
    P
    libreoffice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6516
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6602
    P
    fontconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10770
    P
    libpacemaker-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6615
    P
    gnome-keyring on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64108
    P
    Security update for ucode-intel (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6574
    P
    cron on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9912
    P
    libqt4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6562
    P
    binutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6370
    P
    libecpg6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9946
    P
    mozilla-nspr on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10505
    P
    libid3tag-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6583
    P
    dbus-1-glib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10748
    P
    libjasper-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6432
    P
    libsndfile1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10046
    P
    cups-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6605
    P
    fuse on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6526
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6613
    P
    glib2-lang on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:11041
    P
    libpacemaker-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67442
    P
    Security update for SUSE Manager Proxy 4.1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6584
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6573
    P
    cracklib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6407
    P
    libndp0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6381
    P
    libgraphite2-3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6593
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20152383
    P
    RHSA-2015:2383: pacemaker security, bug fix, and enhancement update (Moderate)
    2015-11-19
    oval:com.ubuntu.precise:def:20151867000
    V
    CVE-2015-1867 on Ubuntu 12.04 LTS (precise) - medium.
    2015-08-12
    oval:com.ubuntu.trusty:def:20151867000
    V
    CVE-2015-1867 on Ubuntu 14.04 LTS (trusty) - medium.
    2015-08-12
    oval:com.redhat.rhsa:def:20151424
    P
    RHSA-2015:1424: pacemaker security and bug fix update (Moderate)
    2015-07-22
    BACK
    clusterlabs pacemaker 1.1.11 -