First published: Mon Jan 18 2016(Updated: )
Session fixation vulnerability in pcsd in pcs before 0.9.157.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ClusterLabs | <=0.9.156 | |
Fedora | =22 | |
Fedora | =23 | |
Red Hat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0721 is considered a medium severity vulnerability due to its potential exploitation to maintain user session control.
To fix CVE-2016-0721, upgrade pcs to version 0.9.157 or later, which addresses the session fixation issue.
CVE-2016-0721 affects pcs versions prior to 0.9.157, as well as specific Fedora and Red Hat Enterprise Linux versions.
CVE-2016-0721 is a session fixation vulnerability that allows unauthorized users to maintain an active session after logout.
Exploiting CVE-2016-0721 can allow an attacker to hijack a user's session and perform unauthorized actions as that user.