ALSA-2023:2652
Dashboard / Vulnerabilities / ALSA-2023:2652
ALSA-2023:2652
Summary: Important: pcs security and bug fix update
Details: The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Security Fix(es): * pcs: webpack: Regression of CVE-2023-28154 fixes in the AlmaLinux (CVE-2023-2319) * rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530) * rubygem-rack: denial of service in header parsing (CVE-2023-27539) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * Command 'pcs config checkpoint diff' does not show configuration differences between checkpoints (BZ#2180697) * Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources (BZ#2180704) * [WebUI] fence levels prevent loading of cluster status (BZ#2183180)
References: https://access.redhat.com/errata/RHSA-2023:2652, https://access.redhat.com/security/cve/CVE-2023-2319, https://access.redhat.com/security/cve/CVE-2023-27530, https://access.redhat.com/security/cve/CVE-2023-27539, https://bugzilla.redhat.com/2176477, https://bugzilla.redhat.com/2179649, https://bugzilla.redhat.com/2190092, https://errata.almalinux.org/9/ALSA-2023-2652.html
Affected packages
Package
Name: pcs
Purl: pkg:rpm/almalinux/pcs
Affected ranges
Type: ECOSYSTEM
Events:
