« Volver al listado

Clusterlabs

Clusterlabs PCS: vulnerabilidades y CVE

Clusterlabs PCS tiene 7 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses1
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-84828Media (6.5)0.14%—10 sept 2026
A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the…
CVE-2023-2319Crítica (9.8)0.97%—17 may 2023
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was…
CVE-2022-2735Alta (7.8)0.32%—6 sept 2022
A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an…
CVE-2022-1049Alta (8.8)2.0%—25 mar 2022
A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired…
CVE-2017-2661Media (6.1)1.2%—12 mar 2018
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.
CVE-2016-0721Alta (8.1)2.3%—21 abr 2017
Session fixation vulnerability in pcsd in pcs before 0.9.157.
CVE-2016-0720Alta (8.8)1.4%—21 abr 2017
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.

Otros productos de Clusterlabs