CVE-2023-2319
- EPSS 0.11%
- Published 17.05.2023 23:15:09
- Last modified 22.01.2025 19:15:09
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat En...
CVE-2022-2735
- EPSS 0.09%
- Published 06.09.2022 18:15:14
- Last modified 21.11.2024 07:01:36
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an authentication token for a hacluste...
CVE-2022-1049
- EPSS 0.14%
- Published 25.03.2022 19:15:10
- Last modified 21.11.2024 06:39:55
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired accounts that have been denied acces...
CVE-2017-2661
- EPSS 0.47%
- Published 12.03.2018 15:29:00
- Last modified 21.11.2024 03:23:55
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.
CVE-2016-0720
- EPSS 0.43%
- Published 21.04.2017 15:59:00
- Last modified 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
CVE-2016-0721
- EPSS 0.45%
- Published 21.04.2017 15:59:00
- Last modified 20.04.2025 01:37:25
Session fixation vulnerability in pcsd in pcs before 0.9.157.