https://seclists.org/oss-sec/2020/q4/83
Published Oct 27, 2020
·Updated
Affected Software
1 affected component
ClusterLabs pacemaker
Frequently Asked Questions
1
What is the severity of CVE-2020-25709?
The severity of CVE-2020-25709 is considered high due to its potential for unauthorized access to critical cluster management controls.
2
How does CVE-2020-25709 affect the system?
CVE-2020-25709 can lead to privilege escalation, allowing non-privileged users to control cluster resources despite restrictions.
3
How do I fix CVE-2020-25709?
To fix CVE-2020-25709, update to the latest version of ClusterLabs Pacemaker that includes the security patches addressing this vulnerability.
4
Who is affected by CVE-2020-25709?
CVE-2020-25709 affects users who have access to Pacemaker daemon IPC and may not be limited by strict user permissions.
5
What should I do if I cannot update to fix CVE-2020-25709?
If an update is not feasible, implement strict access controls and monitor for any unauthorized access to mitigate the impact of CVE-2020-25709.