Lucene search

K
redhatcveRedhat.comRH:CVE-2018-1086
HistoryApr 09, 2018 - 11:48 a.m.

CVE-2018-1086

2018-04-0911:48:48
redhat.com
access.redhat.com
17

0.006 Low

EPSS

Percentile

78.2%

It was found that the REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.