<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 23:12:18 +0000</lastBuildDate>
    <item>
      <title>CVE-2018-1086</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2018-1086</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; redhat pcs&lt;/p&gt;
&lt;p&gt;pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; redhat pcs&lt;/p&gt;
&lt;p&gt;pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2018-1086</guid>
    </item>
    <item>
      <title>USN-7614-1 — pcs vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-7614-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pcs, Ubuntu:Pro:20.04:LTS: pcs, Ubuntu:Pro:22.04:LTS: pcs&lt;/p&gt;
&lt;p&gt;Cedric Buissart discovered that pcs did not correctly handle certain
parameters. An attacker could possibly use this issue to leak sensitive
information or elevate their privileges. This issue only affected
Ubuntu 16.04 LTS. (CVE-2018-1086)&lt;/p&gt;
&lt;p&gt;Ondrej Mular discovered that pcs did not correctly handle Unix socket
permissions. An attacker could possibly use this issue to elevate their
privileges. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2735)&lt;/p&gt;
&lt;p&gt;It was discovered that pcs did not correctly handle PAM authentication.
An attacker could possibly use this issue to bypass authentication
mechanisms. This issue only affected Ubuntu 20.04 LTS and 
Ubuntu 22.04 LTS. (CVE-2022-1049)&lt;/p&gt;
&lt;p&gt;It was discovered that pcs did not correctly handle the validation of
Node names. An attacker could possibly use this issue to execute a
cross-site scripting (XSS) attack. This issue only affected
Ubuntu 16.04 LTS. (CVE-2017-2661)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: pcs, Ubuntu:Pro:20.04:LTS: pcs, Ubuntu:Pro:22.04:LTS: pcs&lt;/p&gt;
&lt;p&gt;Cedric Buissart discovered that pcs did not correctly handle certain
parameters. An attacker could possibly use this issue to leak sensitive
information or elevate their privileges. This issue only affected
Ubuntu 16.04 LTS. (CVE-2018-1086)&lt;/p&gt;
&lt;p&gt;Ondrej Mular discovered that pcs did not correctly handle Unix socket
permissions. An attacker could possibly use this issue to elevate their
privileges. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2735)&lt;/p&gt;
&lt;p&gt;It was discovered that pcs did not correctly handle PAM authentication.
An attacker could possibly use this issue to bypass authentication
mechanisms. This issue only affected Ubuntu 20.04 LTS and 
Ubuntu 22.04 LTS. (CVE-2022-1049)&lt;/p&gt;
&lt;p&gt;It was discovered that pcs did not correctly handle the validation of
Node names. An attacker could possibly use this issue to execute a
cross-site scripting (XSS) attack. This issue only affected
Ubuntu 16.04 LTS. (CVE-2017-2661)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-7614-1</guid>
    </item>
  </channel>
</rss>
