RHSA-2023:2652: Important: pcs security and bug fix update
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.Security Fix(es): pcs: webpack: Regression of CVE-2023-28154 fixes in the Red Hat Enterprise Linux (CVE-2023-2319) rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530) rubygem-rack: denial of service in header parsing (CVE-2023-27539) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Command 'pcs config checkpoint diff' does not show configuration differences between checkpoints (BZ#2180697) Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources (BZ#2180704) [WebUI] fence levels prevent loading of cluster status (BZ#2183180)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:2652?
The severity of RHSA-2023:2652 is denoted as moderate.
How do I fix RHSA-2023:2652?
To fix RHSA-2023:2652, update the pcs packages to version 0.11.4-7.el9_2 or later.
What vulnerabilities are addressed in RHSA-2023:2652?
RHSA-2023:2652 addresses a regression of CVE-2023-28154 and a denial of service issue in the rubygem-rack.
Which software is affected by RHSA-2023:2652?
The pcs and pcs-snmp packages are affected by RHSA-2023:2652 on Red Hat Enterprise Linux.
Is there any workaround for RHSA-2023:2652?
There are no documented workarounds for RHSA-2023:2652; updating the package is recommended.