VDB

CVE-2021-3020

CVE-2021-3020 PUBLISHED

An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setuid program. This allows the hacluster user to invoke certain commands as root (with an attempt to limit this to safe combinations). This user is able to execute an interactive "shell" that isn't limited to the commands specified in hawk_invoke, allowing escalation to root.

EPSS 0.41% · 61.6th percentile

Risk Scores

EPSS Score
0.41%
61.6th percentile

Affected Products

VendorProductVersions
n/an/an/a
clusterlabshawk0

Timeline

  • Mar 14, 2021 CVE Published
  • Aug 26, 2022 EPSS Score
  • Oct 11, 2022 EPSS Score
  • Nov 25, 2022 EPSS Score
  • Jan 10, 2023 EPSS Score
  • Feb 24, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 11, 2023 EPSS Score
  • May 27, 2023 EPSS Score
  • Jul 11, 2023 EPSS Score
  • Aug 26, 2023 EPSS Score
  • Oct 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›