CVE-2022-2735: High severity clusterlabs vulnerability
A security issue was discovered in pcs project. It is caused by incorrect permissions on a unix socket used for internal communication between pcs daemons. A privilege escalation could happen by obtaining authentication token for hacluster user. With the hacluster token, an attacker has complete control over the cluster managed by pcs. The bug was introduced in pcs version 0.10.5 by this bz [1]
[1] https://bugzilla.redhat.com/showbug.cgi?id=1783106
Other sources
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to have complete control over the cluster managed by PCS.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is vulnerability CVE-2022-2735?
Vulnerability CVE-2022-2735 is a privilege escalation vulnerability in the PCS project.
How does vulnerability CVE-2022-2735 occur?
Vulnerability CVE-2022-2735 occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons.
What is the severity of vulnerability CVE-2022-2735?
The severity of vulnerability CVE-2022-2735 is high, with a CVSS score of 7.8.
Which software versions are affected by vulnerability CVE-2022-2735?
The following versions of the PCS project are affected: 0.10.1-2, 0.10.1-2+deb10u1, 0.10.8-1+deb11u1, 0.11.5-1, and 0.11.6-1.
How can vulnerability CVE-2022-2735 be fixed?
To fix vulnerability CVE-2022-2735, update the PCS project to version 0.11.3-2 or higher.