[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2016:2596 -- centos 7 pcs

ID: oval:org.secpod.oval:def:204142Date: (C)2017-03-03   (M)2023-02-20
Class: PATCHFamily: unix




The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. The following packages have been upgraded to a newer upstream version: pcs . Security Fix: * A Cross-Site Request Forgery flaw was found in the pcsd web UI. A remote attacker could provide a specially crafted web page that, when visited by a user with a valid pcsd session, would allow the attacker to trigger requests on behalf of the user, for example removing resources or restarting/removing nodes. * It was found that pcsd did not invalidate cookies on the server side when a user logged out. This could potentially allow an attacker to perform session fixation attacks on pcsd. These issues were discovered by Martin Prpic . Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.

Platform:
CentOS 7
Product:
pcs
Reference:
CESA-2016:2596
CVE-2016-0720
CVE-2016-0721
CVE    2
CVE-2016-0721
CVE-2016-0720
CPE    2
cpe:/a:pcs:pcs
cpe:/o:centos:centos:7

© SecPod Technologies