CVE-2021-3020
Dashboard / Vulnerabilities / CVE-2021-3020
CVE-2021-3020
Published: 26 Aug 2022Last Modified: 8 Jul 2026
Summary:
Details: An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setuid program. This allows the hacluster user to invoke certain commands as root (with an attempt to limit this to safe combinations). This user is able to execute an interactive "shell" that isn't limited to the commands specified in hawk_invoke, allowing escalation to root.
References: https://github.com/ClusterLabs/hawk/releases, https://bugzilla.suse.com/show_bug.cgi?id=1180571, https://github.com/ClusterLabs/crmsh/commit/c538024b8ebd138dc373b005189471d9b77e9c82
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
4.2.1
4.2.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
