Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 23 Mar 2017 15:57:01 +0100
From: Cedric Buissart <cbuissar@...hat.com>
To: oss-security@...ts.openwall.com
Subject: pcs: CVE-2017-2661 Improper node name field validation when creating
 clusters leads to XSS

Hi,

The CVE-2017-2661 has been assigned to the following issue:

Reflected cross-site scripting vulnerability was found in pcs due to
improper validation of Node name field when creating new cluster or adding
existing cluster.

Upstream fix :
* web UI: fixed XSS vulnerability
https://github.com/ClusterLabs/pcs/commit/1874a769b5720ae5430f10c6cedd234430bc703f

Red Hat would like to thank Microsoft for reporting the vulnerability.

-- 
Cedric Buissart,
Product Security

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.