CVE-2018-1086
CVSS5.0
发布时间 :2018-04-12 12:29:00
修订时间 :2018-05-17 11:54:44
NMP    

[原文]pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.


[CNNVD]CNNVD数据暂缺。


[机译]译文暂缺.

- CVSS (基础分值)

CVSS分值: 5 [中等(MEDIUM)]
机密性影响: PARTIAL [很可能造成信息泄露]
完整性影响: NONE [不会对系统完整性产生影响]
可用性影响: NONE [对系统可用性无影响]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: NETWORK [攻击者不需要获取内网访问权或本地访问权]
身份认证: NONE [漏洞利用无需身份认证]

- CWE (弱点类目)

CWE-200 [信息暴露]

- CPE (受影响的平台与产品)

cpe:/a:clusterlabs:pacemaker_command_line_interface:0.9.164
cpe:/a:clusterlabs:pacemaker_command_line_interface:0.10
cpe:/o:debian:debian_linux:9.0
cpe:/o:redhat:enterprise_linux:7.0
cpe:/o:redhat:enterprise_linux:7.5

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1086
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1086
(官方数据源) NVD

- 其它链接及资源

https://access.redhat.com/errata/RHSA-2018:1060
(VENDOR_ADVISORY)  REDHAT  RHSA-2018:1060
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1086
(VENDOR_ADVISORY)  MISC  https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1086
https://www.debian.org/security/2018/dsa-4169
(VENDOR_ADVISORY)  DEBIAN  DSA-4169

- 漏洞信息 (F147161)

Debian Security Advisory 4169-1 (PacketStormID:F147161)
2018-04-11 00:00:00
Debian  debian.org
advisory,info disclosure
linux,redhat,debian
CVE-2018-1086
[点击下载]

Debian Linux Security Advisory 4169-1 - Cedric Buissart from Red Hat discovered an information disclosure bug in pcs, a pacemaker command line interface and GUI. The REST interface normally doesn't allow passing --debug parameter to prevent information leak, but the check wasn't sufficient.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4169-1                   security@debian.org
https://www.debian.org/security/                        Yves-Alexis Perez
April 11, 2018                        https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : pcs
CVE ID         : CVE-2018-1086
Debian Bug     : 895313

CA(c)dric Buissart from Red Hat discovered an information disclosure bug in pcs, a
pacemaker command line interface and GUI. The REST interface normally doesn't
allow passing --debug parameter to prevent information leak, but the check
wasn't sufficient.

For the stable distribution (stretch), this problem has been fixed in
version 0.9.155+dfsg-2+deb9u1.

We recommend that you upgrade your pcs packages.

For the detailed security status of pcs please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pcs

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAlrNxsYACgkQ3rYcyPpX
RFsDlggAy2SHmo+lw4mEkodTH6bISba9cSLBBkalg4bhPmWLHnDw9PFIrUKV6HzB
RoNzoMrsJsi4NDutw0aV9YjyuLYd/OmX8rMP/4zaI/bA4wMkz2EBQ6TkTGIlbYl7
ljTZWSBflfAqU18zIf1gH7jkDN+M3EkWfyJJVCj3KRRwMOCJtgL0GLAJLDB3jn41
Np56spr5F2i+iscpPYVDpJLrPp7A0d+HaVTMLhdlpTK09iUiLiH42MdvYgfdU3z3
LV77zWBR4VgUkqbYcfx2GHupstwC5toYDg771Ukaj69T2N/45wOthlUcSY4dQZlH
8g9WbQwWVJBR4P01nKeUuN/FWgpHtA==
=oRuL
-----END PGP SIGNATURE-----
    

- 漏洞信息 (F147131)

Red Hat Security Advisory 2018-1060-01 (PacketStormID:F147131)
2018-04-11 00:00:00
Red Hat  
advisory,bypass
linux,redhat
CVE-2018-1000119,CVE-2018-1079,CVE-2018-1086
[点击下载]

Red Hat Security Advisory 2018-1060-01 - The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Issues addressed include a bypass vulnerability.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: pcs security update
Advisory ID:       RHSA-2018:1060-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2018:1060
Issue date:        2018-04-10
CVE Names:         CVE-2018-1079 CVE-2018-1086 CVE-2018-1000119 
=====================================================================

1. Summary:

An update for pcs is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Server High Availability (v. 7) - ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Resilient Storage (v. 7) - ppc64le, s390x, x86_64

3. Description:

The pcs packages provide a command-line configuration system for the
Pacemaker and Corosync utilities.

Security Fix(es):

* pcs: Privilege escalation via authorized user malicious REST call
(CVE-2018-1079)

* pcs: Debug parameter removal bypass, allowing information disclosure
(CVE-2018-1086)

* rack-protection: Timing attack in authenticity_token.rb
(CVE-2018-1000119)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in
the References section.

The CVE-2018-1079 issue was discovered by Ondrej Mular (Red Hat) and the
CVE-2018-1086 issue was discovered by Cedric Buissart (Red Hat).

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1534027 - CVE-2018-1000119 rack-protection: Timing attack in authenticity_token.rb
1550243 - CVE-2018-1079 pcs: Privilege escalation via authorized user malicious REST call
1557366 - CVE-2018-1086 pcs: Debug parameter removal bypass, allowing information disclosure

6. Package List:

Red Hat Enterprise Linux Server High Availability (v. 7):

Source:
pcs-0.9.162-5.el7_5.1.src.rpm

ppc64le:
pcs-0.9.162-5.el7_5.1.ppc64le.rpm
pcs-debuginfo-0.9.162-5.el7_5.1.ppc64le.rpm
pcs-snmp-0.9.162-5.el7_5.1.ppc64le.rpm

s390x:
pcs-0.9.162-5.el7_5.1.s390x.rpm
pcs-debuginfo-0.9.162-5.el7_5.1.s390x.rpm
pcs-snmp-0.9.162-5.el7_5.1.s390x.rpm

x86_64:
pcs-0.9.162-5.el7_5.1.x86_64.rpm
pcs-debuginfo-0.9.162-5.el7_5.1.x86_64.rpm
pcs-snmp-0.9.162-5.el7_5.1.x86_64.rpm

Red Hat Enterprise Linux Server Resilient Storage (v. 7):

Source:
pcs-0.9.162-5.el7_5.1.src.rpm

ppc64le:
pcs-0.9.162-5.el7_5.1.ppc64le.rpm
pcs-debuginfo-0.9.162-5.el7_5.1.ppc64le.rpm
pcs-snmp-0.9.162-5.el7_5.1.ppc64le.rpm

s390x:
pcs-0.9.162-5.el7_5.1.s390x.rpm
pcs-debuginfo-0.9.162-5.el7_5.1.s390x.rpm
pcs-snmp-0.9.162-5.el7_5.1.s390x.rpm

x86_64:
pcs-0.9.162-5.el7_5.1.x86_64.rpm
pcs-debuginfo-0.9.162-5.el7_5.1.x86_64.rpm
pcs-snmp-0.9.162-5.el7_5.1.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2018-1079
https://access.redhat.com/security/cve/CVE-2018-1086
https://access.redhat.com/security/cve/CVE-2018-1000119
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2018 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iD8DBQFazH9+XlSAg2UNWIIRAgXpAKCy9AhJzsNaR/BMuuvE1dvARHu/+QCgmcMo
GLJbZqqWMsR6DmK2DtFTz9g=
=kou+
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
    
 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站