CVE-2017-2661: XSS
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.
Other sources
Cross-site scripting vulnerability was found in pcs due to improper validation of Node name field when creating new cluster or adding existing cluster.
Upstream fix : web UI: fixed XSS vulnerability https://github.com/ClusterLabs/pcs/commit/1874a769b5720ae5430f10c6cedd234430bc703f
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2661?
CVE-2017-2661 is classified as a medium severity vulnerability due to the potential for cross-site scripting.
How do I fix CVE-2017-2661?
To fix CVE-2017-2661, upgrade ClusterLabs pcs to version 0.9.157 or later where the vulnerability is addressed.
What causes the CVE-2017-2661 vulnerability?
CVE-2017-2661 is caused by improper validation of the Node name field when creating or adding clusters.
Is CVE-2017-2661 still a risk if I upgrade to version 0.9.157?
No, upgrading to version 0.9.157 or higher eliminates the risk associated with CVE-2017-2661.
What are the potential impacts of CVE-2017-2661?
If exploited, CVE-2017-2661 can allow attackers to execute malicious scripts in the context of the user’s browser.