Lucene search

K
redhatRedHatRHSA-2022:7343
HistoryNov 02, 2022 - 4:05 p.m.

(RHSA-2022:7343) Important: pcs security update

2022-11-0216:05:00
access.redhat.com
182
pcs packages
pacemaker
corosync
rubygem-rack
shell escape
jquery
denial of service

0.035 Low

EPSS

Percentile

91.6%

The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Security Fix(es):

  • rubygem-rack: crafted requests can cause shell escape sequences (CVE-2022-30123)

  • jquery: Prototype pollution in object’s prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.