A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluster user. With the "hacluster" token, this flaw allows an attacker to have complete control over the cluster managed by PCS.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade pcsUpgrade pcs-snmp | Oct 11, 2022 | Sep 6, 2022 |
| Centos_linux | — | Upgrade pcs-snmpUpgrade pcs | Oct 20, 2022 | Sep 6, 2022 |
| Debian | — | Upgrade pcs | Nov 4, 2022 | Sep 6, 2022 |
| Oracle_linux | — | Upgrade pcs-snmpUpgrade pcs | Sep 2, 2022 | Sep 1, 2022 |
| Redhat_linux | — | Upgrade pcsUpgrade pcs-snmp | Oct 20, 2022 | Sep 6, 2022 |
| Rocky_linux | — | Upgrade pcsUpgrade pcs-snmp | Sep 6, 2022 | Sep 1, 2022 |
| Ubuntu | — | Upgrade pcs (Ubuntu Pro) | Jun 26, 2025 | Sep 6, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub