First published: Mon Jan 18 2016(Updated: )
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ClusterLabs | <=0.9.148 | |
Fedora | =22 | |
Fedora | =23 | |
Red Hat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0720 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
To fix CVE-2016-0720, update pcsd to version 0.9.149 or later, which addresses the CSRF vulnerability.
CVE-2016-0720 affects pcs versions prior to 0.9.149, including 0.9.148 and earlier.
An attacker exploiting CVE-2016-0720 could perform unauthorized actions on behalf of a user with a valid pcsd session.
CVE-2016-0720 impacts Fedora versions 22 and 23, as well as Red Hat Enterprise Linux 7.0 and earlier.