CVE-2020-35458: OS Command Injection
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawkremembermeid parameter in the loginfromcookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-35458?
CVE-2020-35458 is a vulnerability in ClusterLabs Hawk 2.x through 2.3.0-x that allows unauthenticated remote attackers to execute code as hauser.
How severe is CVE-2020-35458?
CVE-2020-35458 has a severity rating of 9.8 (critical).
How does CVE-2020-35458 work?
CVE-2020-35458 is a Ruby shell code injection vulnerability that occurs via the hawk_remember_me_id parameter in the login_from_cookie cookie.
Which software versions are affected by CVE-2020-35458?
Versions 2.2.0-12 and 2.3.0-12 of ClusterLabs Hawk are affected by CVE-2020-35458.
How can I fix CVE-2020-35458?
Update ClusterLabs Hawk to a version above 2.3.0-x to fix CVE-2020-35458.