First published: Fri Mar 03 2017(Updated: )
ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/pcs | <0.9.157 | 0.9.157 |
ClusterLabs | <0.9.157 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2661 is classified as a medium severity vulnerability due to the potential for cross-site scripting.
To fix CVE-2017-2661, upgrade ClusterLabs pcs to version 0.9.157 or later where the vulnerability is addressed.
CVE-2017-2661 is caused by improper validation of the Node name field when creating or adding clusters.
No, upgrading to version 0.9.157 or higher eliminates the risk associated with CVE-2017-2661.
If exploited, CVE-2017-2661 can allow attackers to execute malicious scripts in the context of the user’s browser.