Clusterlabs
Clusterlabs PCS: vulnerabilidades y CVE
Clusterlabs PCS tiene 7 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-84828 | Media (6.5) | 0.14% | — | 10 sept 2026 | A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the… |
| CVE-2023-2319 | Crítica (9.8) | 0.97% | — | 17 may 2023 | It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was… |
| CVE-2022-2735 | Alta (7.8) | 0.32% | — | 6 sept 2022 | A vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between PCS daemons. A privilege escalation could happen by obtaining an… |
| CVE-2022-1049 | Alta (8.8) | 2.0% | — | 25 mar 2022 | A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to login when using PAM authentication. Therefore, unprivileged expired… |
| CVE-2017-2661 | Media (6.1) | 1.2% | — | 12 mar 2018 | ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster. |
| CVE-2016-0721 | Alta (8.1) | 2.3% | — | 21 abr 2017 | Session fixation vulnerability in pcsd in pcs before 0.9.157. |
| CVE-2016-0720 | Alta (8.8) | 1.4% | — | 21 abr 2017 | Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. |