PT-2015-6793 · Pcs+2 · Pcs+2

Adam Mariš

+1

·

Published

2015-09-01

·

Updated

2023-02-13

·

CVE-2015-5189

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PCS versions 0.9.139 and earlier
Description A race condition exists in the pcsd web UI backend, allowing remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated. This issue can be exploited to send a request that would be evaluated as originating from a different user, potentially allowing the attacker to perform actions with permissions of a more privileged user.
Recommendations For PCS versions 0.9.139 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Weakness Enumeration

Related Identifiers

CESA-2015_1700
CVE-2015-5189
RHSA-2015:1700
RHSA-2015_1700

Affected Products

Centos
Pcs
Red Hat