← Vulnerability feed

Vulnerability record · CVE-2023-2319 · published 17 May 2023

CVE-2023-2319: Clusterlabs pcs vulnerability

Clusterlabs · Pcs

It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linux 9.2.

9.8 CVSS 3.1 Critical EPSS 0.97% · top 39.3%
9.8CVSS 3.1 base score
0.97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linux 9.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2319 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-1049Clusterlabs pcs improper authentication vulnerabilityA flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to logi…EPSS 2.0%8.8CVE-2016-0720Clusterlabs pcs cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.EPSS 1.4%8.1CVE-2016-0721Clusterlabs pcs vulnerabilitySession fixation vulnerability in pcsd in pcs before 0.9.157.EPSS 2.3%7.8CVE-2022-2735Clusterlabs pcs incorrect default permissions vulnerabilityA vulnerability was found in the PCS project. This issue occurs due to incorrect permissions on a Unix socket used for internal communication between…EPSS 0.32%7.5CVE-2016-7797Clusterlabs pacemaker vulnerabilityPacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthent…EPSS 3.3%7.5CVE-2015-1867Redhat enterprise linux high availability permissions and access controls vulnerabilityPacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.EPSS 3.0%6.8CVE-2015-1848Fedora pacemaker configuration system vulnerabilityThe pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote atta…EPSS 2.4%6.1CVE-2017-2661Clusterlabs pcs cross-site scripting vulnerabilityClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creat…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-2319), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.