Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-12235

Опубликовано: 05 апр. 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-12235: pcs security update (IMPORTANT)

[0.11.3-4.el9_1.3]

  • Fixed a vulnerability in pcs-web-ui-node-modules
  • Resolves: rhbz#2179900

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

pcs

0.11.3-4.el9_1.3

pcs-snmp

0.11.3-4.el9_1.3

Oracle Linux x86_64

pcs

0.11.3-4.el9_1.3

pcs-snmp

0.11.3-4.el9_1.3

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.1
redhat
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
nvd
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

CVSS3: 9.8
debian
больше 2 лет назад

Webpack 5 before 5.76.0 does not avoid cross-realm object access. Impo ...

CVSS3: 9.8
github
больше 2 лет назад

Cross-realm object access in Webpack 5