CVE-2018-16877

HIGH EPSS 32.2%
Published Apr 18, 20197y ago · Modified Jun 17, 20262w ago
7.8 CVSS 3.1
High
Find Similar
Published Apr 18, 2019 7y ago
Last Modified Jun 17, 2026 2w ago

Description

A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it with other IPC weaknesses, to achieve local privilege escalation.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
32.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-287 Improper Authentication Authentication

Affected Products 22

VendorProductVersionRange
clusterlabspacemaker* ≤2.0.0
canonicalubuntu_linux16.04any
canonicalubuntu_linux18.04any
canonicalubuntu_linux18.10any
canonicalubuntu_linux19.04any
fedoraprojectfedora28any
fedoraprojectfedora29any
fedoraprojectfedora30any
debiandebian_linux9.0any
opensuseleap15.0any
opensuseleap42.3any
redhatenterprise_linux8.0any
redhatenterprise_linux_eus8.1any
redhatenterprise_linux_eus8.2any
redhatenterprise_linux_eus8.4any
redhatenterprise_linux_eus8.6any
redhatenterprise_linux_server_aus8.2any
redhatenterprise_linux_server_aus8.4any
redhatenterprise_linux_server_aus8.6any
redhatenterprise_linux_server_tus8.2any
redhatenterprise_linux_server_tus8.4any
redhatenterprise_linux_server_tus8.6any

References 13

  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00012.html
    Mailing ListThird Party Advisory
  • lists.opensuse.org http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00034.html
    Mailing ListThird Party Advisory
  • securityfocus.com http://www.securityfocus.com/bid/108042
    Broken Link
  • access.redhat.com https://access.redhat.com/errata/RHSA-2019:1278
    Third Party Advisory
  • access.redhat.com https://access.redhat.com/errata/RHSA-2019:1279
    Third Party Advisory
  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16877
    Issue TrackingPatchThird Party Advisory
  • github.com https://github.com/ClusterLabs/pacemaker/pull/1749
    PatchThird Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2021/01/msg00007.html
    Mailing ListThird Party Advisory
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3GCWFO7GL6MBU6C4BGFO3P6L77DIBBF3/
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FY4M4RMIG2POKC6OOFQODGKPRYXHET2F/
  • lists.fedoraproject.org https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HR6QUYGML735EI3HEEHYRDW7EG73BUH2/
  • security.gentoo.org https://security.gentoo.org/glsa/202309-09
  • usn.ubuntu.com https://usn.ubuntu.com/3952-1/
    Third Party Advisory

Remediation

  • bugzilla.redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16877
    Issue TrackingPatchThird Party Advisory
  • github.com https://github.com/ClusterLabs/pacemaker/pull/1749
    PatchThird Party Advisory