Vulnerability record · CVE-2021-3020 · published 26 August 2022
CVE-2021-3020: Clusterlabs hawk improper privilege management vulnerability
Clusterlabs · Hawk
An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setuid program. This allows the hacluster user to invoke certain commands as root (with an attempt to limit this to safe combinations). This user is able to execute an interactive "shell" that isn't limited to the commands specified in hawk_invoke, allowing escalation to root.
Description
An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (built from tools/hawk_invoke.c), intended to be used as a setuid program. This allows the hacluster user to invoke certain commands as root (with an attempt to limit this to safe combinations). This user is able to execute an interactive "shell" that isn't limited to the commands specified in hawk_invoke, allowing escalation to root.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1180571 | Permissions Required |
| https://github.com/ClusterLabs/crmsh/commit/c538024b8ebd138dc373b005189471d9b77e9c82 | PatchThird Party Advisory |
| https://github.com/ClusterLabs/hawk/releases | Release NotesThird Party Advisory |
| https://bugzilla.suse.com/show_bug.cgi?id=1180571 | Permissions Required |
| https://github.com/ClusterLabs/crmsh/commit/c538024b8ebd138dc373b005189471d9b77e9c82 | PatchThird Party Advisory |
| https://github.com/ClusterLabs/hawk/releases | Release NotesThird Party Advisory |
Track CVE-2021-3020 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3020), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.