Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Tomáš Jelínek

Pesquisador deRed Hat
#19557de 53,635
13.4CVSS total
Vulnerabilidades · 2
Média
1
Alta
1
PT-2015-6793
4.9
2015-09-01
Pcs · Pcs · CVE-2015-5189
**Name of the Vulnerable Software and Affected Versions** PCS versions 0.9.139 and earlier **Description** A race condition exists in the pcsd web UI backend, allowing remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated. This issue can be exploited to send a request that would be evaluated as originating from a different user, potentially allowing the attacker to perform actions with permissions of a more privileged user. **Recommendations** For PCS versions 0.9.139 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2015-6794
8.5
2015-09-01
Pcs · Pcs · CVE-2015-5190
**Name of the Vulnerable Software and Affected Versions** PCs versions 0.9.139 and earlier **Description** The issue allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL. This is related to the pcsd web UI. **Recommendations** For versions 0.9.139 and earlier, consider restricting access to the pcsd web UI until a fix is available. As a temporary workaround, avoid using URLs with "escape characters" in the pcsd web UI to minimize the risk of exploitation.