CVE-2020-35458

An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.
Configurations

Configuration 1

cpe:2.3:a:clusterlabs:hawk:2.3.0-12:*:*:*:*:*:*:*
cpe:2.3:a:clusterlabs:hawk:2.2.0-12:*:*:*:*:*:*:*

Information

Published : 2021-01-12 03:15

Updated : 2021-07-21 11:39


NVD link : CVE-2020-35458

Mitre link : CVE-2020-35458

Products Affected
No products.
CWE