Date: Thu, 23 Mar 2017 15:57:01 +0100 From: Cedric Buissart <cbuissar@...hat.com> To: oss-security@...ts.openwall.com Subject: pcs: CVE-2017-2661 Improper node name field validation when creating clusters leads to XSS Hi, The CVE-2017-2661 has been assigned to the following issue: Reflected cross-site scripting vulnerability was found in pcs due to improper validation of Node name field when creating new cluster or adding existing cluster. Upstream fix : * web UI: fixed XSS vulnerability https://github.com/ClusterLabs/pcs/commit/1874a769b5720ae5430f10c6cedd234430bc703f Red Hat would like to thank Microsoft for reporting the vulnerability. -- Cedric Buissart, Product Security
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.