4.3
CVSSv2

CVE-2017-2661

Published: 12/03/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.

Vulnerable Product Search on Vulmon Subscribe to Product

clusterlabs pcs

Vendor Advisories

Debian Bug report logs - #858379 pcs: CVE-2017-2661: Improper node name field validation when creating clusters leads to XSS Package: src:pcs; Maintainer for src:pcs is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 21 Mar 2017 18 ...