Vincent Berg discovered that CRM shell incorrectly handled certain commands. An local attacker could possibly use this issue to execute arbitrary code via shell code injection to the crm history commandline.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4.2.0-2ubuntu1.1", "binary_name": "crmsh" }, { "binary_version": "4.2.0-2ubuntu1.1", "binary_name": "crmsh-doc" } ] }