Vulnerability Description
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linux 9.2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Clusterlabs | Pcs | 0.11.4-6.el9 |
| Redhat | Enterprise Linux High Availability | 9.0 |
| Redhat | Enterprise Linux High Availability Eus | 9.2 |
References
- https://access.redhat.com/errata/RHSA-2023:2652Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-2319Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2190092Issue Tracking
- https://access.redhat.com/errata/RHSA-2023:2652Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-2319Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2190092Issue Tracking
FAQ
What is CVE-2023-2319?
CVE-2023-2319 is a vulnerability with a CVSS score of 9.8 (CRITICAL). It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS pack...
How severe is CVE-2023-2319?
CVE-2023-2319 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-2319?
Check the references section above for vendor advisories and patch information. Affected products include: Clusterlabs Pcs, Redhat Enterprise Linux High Availability, Redhat Enterprise Linux High Availability Eus.