RSS   Vulnerabilities for
'Pacemaker/corosync configuration system'
   RSS

2015-09-03
 
CVE-2015-5190

 

 
The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.

 
 
CVE-2015-5189

 

 
Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.

 


Copyright 2024, cxsecurity.com

 

Back to Top