[RHSA-2021:4142] pcs security, bug fix, and enhancement update

Severity Low
Affected Packages 8
CVEs 3

The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

The following packages have been upgraded to a later upstream version: pcs (0.10.10). (BZ#1935594)

Security Fix(es):

  • jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces (CVE-2020-7656)

  • jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods (CVE-2020-11023)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.

ID
RHSA-2021:4142
Severity
low
URL
https://access.redhat.com/errata/RHSA-2021:4142
Published
2021-11-09T00:00:00
(2 years ago)
Modified
2021-11-09T00:00:00
(2 years ago)
Rights
Copyright 2021 Red Hat, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/pcs?arch=x86_64&distro=redhat-8 redhat pcs < 0.10.10-4.el8 redhat-8 x86_64
Affected pkg:rpm/redhat/pcs?arch=s390x&distro=redhat-8 redhat pcs < 0.10.10-4.el8 redhat-8 s390x
Affected pkg:rpm/redhat/pcs?arch=ppc64le&distro=redhat-8 redhat pcs < 0.10.10-4.el8 redhat-8 ppc64le
Affected pkg:rpm/redhat/pcs?arch=aarch64&distro=redhat-8 redhat pcs < 0.10.10-4.el8 redhat-8 aarch64
Affected pkg:rpm/redhat/pcs-snmp?arch=x86_64&distro=redhat-8 redhat pcs-snmp < 0.10.10-4.el8 redhat-8 x86_64
Affected pkg:rpm/redhat/pcs-snmp?arch=s390x&distro=redhat-8 redhat pcs-snmp < 0.10.10-4.el8 redhat-8 s390x
Affected pkg:rpm/redhat/pcs-snmp?arch=ppc64le&distro=redhat-8 redhat pcs-snmp < 0.10.10-4.el8 redhat-8 ppc64le
Affected pkg:rpm/redhat/pcs-snmp?arch=aarch64&distro=redhat-8 redhat pcs-snmp < 0.10.10-4.el8 redhat-8 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...