Description
Session fixation vulnerability in pcsd in pcs before 0.9.157.
References (8)
Core 8
Core References
Patch x_refsource_confirm
https://github.com/ClusterLabs/pcs/commit/bc6ad9086857559db57f4e3e6de66762291c0774
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1299615
Patch x_refsource_confirm
https://github.com/ClusterLabs/pcs/commit/e9b28833d54a47ec441f6dbad0db96e1fc662a5b
Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178384.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/97977
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-2596.html
Patch x_refsource_confirm
https://github.com/ClusterLabs/pcs/commit/acdbbe8307e6f4a36b2c7754765e732e43fe8d17
Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178261.html
Scores
CVSS v3
8.1
EPSS
0.0229
EPSS Percentile
81.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Details
CWE
CWE-384
Status
published
Products (4)
clusterlabs/pcs
< 0.9.156
fedoraproject/fedora
22
fedoraproject/fedora
23
redhat/enterprise_linux
7.0
Published
Apr 21, 2017
Tracked Since
Feb 18, 2026