VulnerabilityModified
CVE-2016-0721
Session fixation vulnerability in pcsd in pcs before 0.9.157.
HIGH 8.1EPSS 2.29%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Session fixation vulnerability in pcsd in pcs before 0.9.157.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- clusterlabs/pcs · fedoraproject/fedora · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178261.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178384.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2596.htmlThird Party Advisory
- http://www.securityfocus.com/bid/97977Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1299615Issue Tracking, Patch, Third Party Advisory
- https://github.com/ClusterLabs/pcs/commit/acdbbe8307e6f4a36b2c7754765e732e43fe8d17Patch
- https://github.com/ClusterLabs/pcs/commit/bc6ad9086857559db57f4e3e6de66762291c0774Patch
- https://github.com/ClusterLabs/pcs/commit/e9b28833d54a47ec441f6dbad0db96e1fc662a5bPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178261.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-March/178384.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2596.htmlThird Party Advisory
- http://www.securityfocus.com/bid/97977Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1299615Issue Tracking, Patch, Third Party Advisory
- https://github.com/ClusterLabs/pcs/commit/acdbbe8307e6f4a36b2c7754765e732e43fe8d17Patch
- https://github.com/ClusterLabs/pcs/commit/bc6ad9086857559db57f4e3e6de66762291c0774Patch
- https://github.com/ClusterLabs/pcs/commit/e9b28833d54a47ec441f6dbad0db96e1fc662a5bPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.