CVE-2023-2319

CRITICAL

Red Hat Enterprise Linux 9.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linux 9.2.

Scores

CVSS v3 9.8
EPSS 0.0013
EPSS Percentile 32.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

Status published
Products (3)
clusterlabs/pcs 0.11.4-6.el9
redhat/enterprise_linux_high_availability 9.0
redhat/enterprise_linux_high_availability_eus 9.2
Published May 17, 2023
Tracked Since Feb 18, 2026