CVE-2016-0720

Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
clusterlabspcs
𝑥
≤ 0.9.148
redhatenterprise_linux
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pcs
bookworm
0.11.5-1+deb12u1
fixed
bullseye
0.10.8-1+deb11u1
fixed
bullseye (security)
0.10.8-1+deb11u1
fixed
sid
0.11.7-2
fixed
trixie
0.11.7-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pcs
precise
dne
trusty
dne
wily
dne
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
pcs
RHEL 7
0:0.9.152-10.el7
fixed