{"affected":[{"ecosystem_specific":{"binaries":[{"crmsh":"4.1.0+git.1607482714.9633b80d-2.50.1","crmsh-scripts":"4.1.0+git.1607482714.9633b80d-2.50.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise High Availability Extension 12 SP4","name":"crmsh","purl":"pkg:rpm/suse/crmsh&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.1.0+git.1607482714.9633b80d-2.50.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"crmsh":"4.1.0+git.1607482714.9633b80d-2.50.1","crmsh-scripts":"4.1.0+git.1607482714.9633b80d-2.50.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise High Availability Extension 12 SP5","name":"crmsh","purl":"pkg:rpm/suse/crmsh&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP5"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"4.1.0+git.1607482714.9633b80d-2.50.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for crmsh fixes the following issue:\n\n- CVE-2020-35459: Fixed a privilege escalation in hawk_invoke (bsc#1179999).\n","id":"SUSE-SU-2021:0083-1","modified":"2021-01-12T13:32:01Z","published":"2021-01-12T13:32:01Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20210083-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179999"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35459"}],"related":["CVE-2020-35459"],"summary":"Security update for crmsh","upstream":["CVE-2020-35459"]}