Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2661

Опубликовано: 12 мар. 2018
Источник: debian
EPSS Низкий

Описание

ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pcsfixed0.9.155+dfsg-2package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1428948

  • https://github.com/ClusterLabs/pcs/commit/1874a769b5720ae5430f10c6cedd234430bc703f

  • https://www.openwall.com/lists/oss-security/2017/03/23/2

EPSS

Процентиль: 60%
0.00397
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 8 лет назад

ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.

CVSS3: 6.1
redhat
почти 9 лет назад

ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.

CVSS3: 6.1
nvd
почти 8 лет назад

ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.

CVSS3: 6.1
github
больше 3 лет назад

ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.

EPSS

Процентиль: 60%
0.00397
Низкий