Lucene search

K
osvGoogleOSV:CVE-2018-1086
HistoryApr 12, 2018 - 4:29 p.m.

CVE-2018-1086

2018-04-1216:29:00
Google
osv.dev
3

0.006 Low

EPSS

Percentile

78.2%

pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.

Rows per page:
1-10 of 1411