Lucene search

K
osvGoogleOSV:RLSA-2023:2652
HistoryMay 25, 2023 - 7:53 p.m.

Important: pcs security and bug fix update

2023-05-2519:53:02
Google
osv.dev
18
pcs packages
configuration system
pacemaker
corosync
security fixes
cve-2023-28154
cve-2023-2319
rubygem-rack
denial of service
cve-2023-27530
cve-2023-27539
bug fixes
bz#2180697
bz#2180704
bz#2183180

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

64.8%

The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Security Fix(es):

  • pcs: webpack: Regression of CVE-2023-28154 fixes in the Rocky Linux (CVE-2023-2319)

  • rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530)

  • rubygem-rack: denial of service in header parsing (CVE-2023-27539)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Command β€˜pcs config checkpoint diff’ does not show configuration differences between checkpoints (BZ#2180697)

  • Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources (BZ#2180704)

  • [WebUI] fence levels prevent loading of cluster status (BZ#2183180)

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

64.8%