VYPR
Vendor

Pacemaker\/corosync Configuration System Project

Sign in to watch
Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2015-51900.000.01Sep 3, 2015The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.
CVE-2015-51890.000.00Sep 3, 2015Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.