A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied access could still login.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade pcs-snmpUpgrade pcs | Nov 14, 2022 | Mar 25, 2022 |
| Centos_linux | — | Upgrade pcsUpgrade pcs-snmp | Nov 9, 2022 | Mar 25, 2022 |
| Debian | — | Upgrade pcs | Sep 16, 2022 | Mar 25, 2022 |
| Oracle_linux | — | Upgrade pcs-snmpUpgrade pcs | Nov 29, 2022 | Mar 17, 2022 |
| Redhat_linux | — | Upgrade pcsNo solution existsUpgrade pcs-snmp | Nov 9, 2022 | Mar 25, 2022 |
| Rocky_linux | — | Upgrade pcsUpgrade pcs-snmp | Mar 12, 2024 | Mar 25, 2022 |
| Ubuntu | — | Upgrade pcs (Ubuntu Pro) | Jun 26, 2025 | Mar 25, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub