RHSA-2022:2256: Important: pcs security update
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.Security Fix(es): sinatra: path traversal possible outside of publicdir when serving static files (CVE-2022-29970) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pcsto a version that resolves this vulnerability.Fixed in 0.10.8-1.el8_4.1 - Upgrade
Upgrade
redhat/pcs-snmpto a version that resolves this vulnerability.Fixed in 0.10.8-1.el8_4.1 - Upgrade
Upgrade
redhat/pcsto a version that resolves this vulnerability.Fixed in 0.10.8-1.el8_4.1.aa - Upgrade
Upgrade
redhat/pcs-snmpto a version that resolves this vulnerability.Fixed in 0.10.8-1.el8_4.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:2256?
The severity of RHSA-2022:2256 is classified as important.
How do I fix RHSA-2022:2256?
To fix RHSA-2022:2256, upgrade the pcs and pcs-snmp packages to version 0.10.8-1.el8_4.1 or later.
What packages are affected by RHSA-2022:2256?
The affected packages for RHSA-2022:2256 are pcs and pcs-snmp.
What vulnerability does RHSA-2022:2256 address?
RHSA-2022:2256 addresses a path traversal vulnerability in the sinatra library (CVE-2022-29970).
Is a system reboot required after applying the fix for RHSA-2022:2256?
No, a system reboot is not required after applying the fix for RHSA-2022:2256.