Vulnerability Name:

CVE-2021-3020 (CCN-234592)

Assigned:2021-01-05
Published:2021-01-05
Updated:2022-09-02
Summary:An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setuid program. This allows the hacluster user to invoke certain commands as root (with an attempt to limit this to safe combinations). This user is able to execute an interactive "shell" that isn't limited to the commands specified in hawk_invoke, allowing escalation to root.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-77
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2021-3020

Source: MISC
Type: Permissions Required
https://bugzilla.suse.com/show_bug.cgi?id=1180571

Source: XF
Type: UNKNOWN
clusterlabs-cve20213020-priv-esc(234592)

Source: CCN
Type: ClusterLabs GIT Repository
Fix: bootstrap: setup authorized ssh access for hacluster(CVE-2020-35459

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/ClusterLabs/crmsh/commit/c538024b8ebd138dc373b005189471d9b77e9c82

Source: MISC
Type: Release Notes, Third Party Advisory
https://github.com/ClusterLabs/hawk/releases

Source: CCN
Type: Mend Vulnerability Database
CVE-2021-3020

Vulnerable Configuration:Configuration 1:
  • cpe:/a:clusterlabs:hawk:*:*:*:*:*:*:*:* (Version <= 2.3.0-15)

  • Configuration CCN 1:
  • cpe:/a:clusterlabs:hawk:2.3.0-15:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:102236
    P
    Security update for libslirp (Important)
    2022-04-29
    oval:org.opensuse.security:def:97292
    P
    Security update for crmsh (Important)
    2021-03-17
    oval:org.opensuse.security:def:8265
    P
    Security update for crmsh (Important)
    2021-03-17
    oval:org.opensuse.security:def:111265
    P
    Security update for crmsh (Important)
    2021-03-14
    oval:org.opensuse.security:def:67064
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:97287
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:98838
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:8332
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:108902
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:118640
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:91888
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:97288
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:8378
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:109544
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:95523
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:5975
    P
    Security update for s390-tools (Important)
    2021-03-12
    oval:org.opensuse.security:def:102878
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:76132
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:96188
    P
    Security update for crmsh (Important)
    2021-03-12
    oval:org.opensuse.security:def:19524
    P
    Security update for crmsh (Important)
    2021-03-11
    oval:org.opensuse.security:def:4289
    P
    Security update for crmsh (Important)
    2021-03-08
    oval:org.opensuse.security:def:19573
    P
    Security update for crmsh (Important)
    2021-03-08
    oval:org.opensuse.security:def:19621
    P
    Security update for crmsh (Important)
    2021-03-08
    oval:org.opensuse.security:def:125105
    P
    Security update for crmsh (Important)
    2021-03-08
    BACK
    clusterlabs hawk *
    clusterlabs hawk 2.3.0-15