An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawkremembermeid parameter in the loginfrom_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.
{
"cpe": [
"cpe:2.3:a:clusterlabs:hawk:2.2.0-12:*:*:*:*:*:*:*",
"cpe:2.3:a:clusterlabs:hawk:2.3.0-12:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.2.0-12"
},
{
"last_affected": "2.3.0-12"
}
],
"source": "CPE_STRING"
}