Lucene search

K
cvelistMitreCVELIST:CVE-2020-35458
HistoryJan 12, 2021 - 2:21 p.m.

CVE-2020-35458

2021-01-1214:21:23
mitre
www.cve.org
5
clusterlabs
hawk
remote code execution

AI Score

9.7

Confidence

High

EPSS

0.011

Percentile

84.7%

An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.

AI Score

9.7

Confidence

High

EPSS

0.011

Percentile

84.7%

Related for CVELIST:CVE-2020-35458