CVE-2010-2496

MEDIUM

cluster_glue < 1.0.6 and pacemaker < 1.1.3 - Password Exposure via Command Line Parameters

Title source: llm
STIX 2.1

Description

stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attackers to gain access to passwords of the HA stack and potentially influence its operations. This is fixed in cluster-glue 1.0.6 and newer, and pacemaker 1.1.3 and newer.

References (1)

Core 1
Core References
Issue Tracking, Mailing List, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2010-2496

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 13.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (2)
clusterlabs/cluster_glue < 1.0.6
clusterlabs/pacemaker < 1.1.3
Published Oct 18, 2021
Tracked Since Feb 18, 2026