CVE-2015-5189
pcs: Incorrect authorization when using pcs web UI
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.
Vulnerabilidad de condición de carrera de pcsd en PCS 0.9.139 y en versiones anteriores utiliza una variable global para validar nombres de usuarios, lo que permite a usuarios remotos autenticados para obtener privilegios mediante el envío de un comando que se comprueba por seguridad tras autenticarse otro usuario.
A race condition was found in the way the pcsd web UI backend performed authorization of user requests. An attacker could use this flaw to send a request that would be evaluated as originating from a different user, potentially allowing the attacker to perform actions with permissions of a more privileged user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-07-01 CVE Reserved
- 2015-09-02 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-863: Incorrect Authorization
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2015-1700.html | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1252805 | 2015-09-01 | |
https://access.redhat.com/security/cve/CVE-2015-5189 | 2015-09-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pacemaker\/corosync Configuration System Project Search vendor "Pacemaker\/corosync Configuration System Project" | Pacemaker\/corosync Configuration System Search vendor "Pacemaker\/corosync Configuration System Project" for product "Pacemaker\/corosync Configuration System" | <= 0.9.139 Search vendor "Pacemaker\/corosync Configuration System Project" for product "Pacemaker\/corosync Configuration System" and version " <= 0.9.139" | - |
Affected
|