CVE-2016-0720: CSRF
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
Other sources
The pcsd web UI is vulnerable to Cross-Site Request Forgery (CSRF). A remote attacker could provide a specially crafted web page that, when visited by a user with a valid pcsd session, would allow the attacker to trigger requests on behalf of the user, for example removing resources, restarting/removing nodes, etc.
Each request includes 'X-Requested-With: XMLHttpRequest' but this header is not checked server side.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0720?
CVE-2016-0720 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2016-0720?
To fix CVE-2016-0720, update pcsd to version 0.9.149 or later, which addresses the CSRF vulnerability.
Which versions of pcs are affected by CVE-2016-0720?
CVE-2016-0720 affects pcs versions prior to 0.9.149, including 0.9.148 and earlier.
What impact can an attacker have using CVE-2016-0720?
An attacker exploiting CVE-2016-0720 could perform unauthorized actions on behalf of a user with a valid pcsd session.
Are there any specific operating systems impacted by CVE-2016-0720?
CVE-2016-0720 impacts Fedora versions 22 and 23, as well as Red Hat Enterprise Linux 7.0 and earlier.