Clusterlabs develops a focused suite of high-availability and cluster-management tools centered on Pacemaker, its widely deployed open-source resource manager, along with configuration utilities, fencing agents, and booth quorum systems that underpin critical infrastructure resilience. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the exposure recurs through authentication weaknesses, unsafe link and path resolution in privileged contexts, and OS command injection in cluster-control interfaces that are characteristic of system-level software with broad privilege requirements. The product portfolio's role in managing failover and node state means that successful exploitation can compromise availability and integrity across entire service clusters, making even modestly represented flaws a material risk to defenders. Defenders should prioritize inventory and patching of Pacemaker and its agent ecosystem, particularly in production cluster configurations; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clusterlabs over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35458CRITICAL An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. T | Jan 12, 2021 | 9.8 | 32 | NO | NO |
CVE-2023-2319CRITICAL It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023 | May 17, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-3020HIGH An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setuid | Aug 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-39976CRITICAL log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered. | Aug 8, 2023 | 9.8 | 27 | NO | NO |
CVE-2019-3885HIGH A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs. | Apr 18, 2019 | 7.5 | 26 | NO | NO |
CVE-2022-2735HIGH A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escal | Sep 6, 2022 | 7.8 | 25 | NO | NO |
CVE-2018-16877HIGH A flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could use this flaw, and combine it wit | Apr 18, 2019 | 7.8 | 25 | NO | NO |
CVE-2016-7035HIGH An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could us | Sep 10, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-1086HIGH pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the / | Apr 12, 2018 | 7.5 | 25 | NO | NO |
CVE-2022-1049HIGH A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication | Mar 25, 2022 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clusterlabs.
Media articles that mention a CVE ID that affects a product developed by Clusterlabs — matched by CVE ID, not by vendor name.