{"id":"MGASA-2021-0049","summary":"Updated crmsh packages fix security vulnerability","details":"The crm configure and hb_report commands failed to sanitize sensitive\ninformation by default (bsc#1163581).\n\nAn issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers\nable to call \"crm history\" (when \"crm\" is run) were able to execute commands\nvia shell code injection to the crm history commandline, potentially allowing\nescalation of privileges (CVE-2020-25459).\n\nThe crmsh package has been updated to the latest git snapshot and patched for\nCVE-2020-25459, fixing these issues and several others.\n","modified":"2026-04-16T04:43:00.682461869Z","published":"2021-01-22T23:50:14Z","upstream":["CVE-2020-25459"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0049.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=27444"},{"type":"WEB","url":"https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00032.html"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/RKSUG2OZN3Y2FQVQ55HP5MZIQZXZ5OD6/"}],"affected":[{"package":{"name":"crmsh","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/crmsh?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.0-0.39d42c2.1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0049.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}