[Apollo] Advisories Red Hat Advisories Statistics light light Login

RHSA-2023:2652

Security
Issued at: 2023-05-09
launch
Open original
Override

Synopsis

Important: pcs security and bug fix update



Description

The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Security Fix(es):

* pcs: webpack: Regression of CVE-2023-28154 fixes in the Red Hat Enterprise Linux (CVE-2023-2319)

* rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530)

* rubygem-rack: denial of service in header parsing (CVE-2023-27539)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* Command 'pcs config checkpoint diff' does not show configuration differences between checkpoints (BZ#2180697)

* Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources (BZ#2180704)

* [WebUI] fence levels prevent loading of cluster status (BZ#2183180)



Affected products

Red Hat Enterprise Linux for ARM 64 - 9 Red Hat Enterprise Linux for IBM z Systems - 9 Red Hat Enterprise Linux for Power, little endian - 9 Red Hat Enterprise Linux for x86_64 - 9

Fixes

2176477 2179649 2190092

CVEs

CVE-2023-2319 CVE-2023-27530 CVE-2023-27539

Affected packages

pcs-0:0.11.4-7.el9_2.aarch64 pcs-0:0.11.4-7.el9_2.ppc64le pcs-0:0.11.4-7.el9_2.s390x pcs-0:0.11.4-7.el9_2.src pcs-0:0.11.4-7.el9_2.x86_64 pcs-snmp-0:0.11.4-7.el9_2.aarch64 pcs-snmp-0:0.11.4-7.el9_2.ppc64le pcs-snmp-0:0.11.4-7.el9_2.s390x pcs-snmp-0:0.11.4-7.el9_2.x86_64