Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1867
Reference (s):
- BID:74231
- URL: http://www.securityfocus.com/bid/74231
- https://bugzilla.redhat.com/show_bug.cgi?id=1211370
- https://github.com/ClusterLabs/pacemaker/commit/84ac07c
- FEDORA:FEDORA-2015-e5e36bbb87