Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection blocking).
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pacemaker | Jul 30, 2024 | Nov 23, 2013 |
| Oracle_linux | — | Upgrade pacemakerUpgrade pacemaker-ctsUpgrade pacemaker-docUpgrade pacemaker-cliUpgrade pacemaker-cluster-libsUpgrade pacemaker-remoteUpgrade pacemaker-libsUpgrade pacemaker-libs-devel | Oct 16, 2024 | Nov 23, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub