CESA-2016:2596 -- centos 7 pcsID: oval:org.secpod.oval:def:204142 | Date: (C)2017-03-03 (M)2023-02-20 |
Class: PATCH | Family: unix |
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. The following packages have been upgraded to a newer upstream version: pcs . Security Fix: * A Cross-Site Request Forgery flaw was found in the pcsd web UI. A remote attacker could provide a specially crafted web page that, when visited by a user with a valid pcsd session, would allow the attacker to trigger requests on behalf of the user, for example removing resources or restarting/removing nodes. * It was found that pcsd did not invalidate cookies on the server side when a user logged out. This could potentially allow an attacker to perform session fixation attacks on pcsd. These issues were discovered by Martin Prpic . Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section.