CVE-2023-2319 is a critical security regression in Red Hat Enterprise Linux 9.2, specifically affecting the PCS package within Red Hat Enterprise Linux High Availability. This vulnerability, with a CVSS score of 9.8, stems from the failure to include a previously addressed Webpack fix (CVE-2023-28154) in the RHBA-2023:2151 erratum. Due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability, this flaw presents a significant risk. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered considerable community discussion, indicating awareness and potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.11.4-6.el9CPE matchmatch criteria | cpe:2.3:a:clusterlabs:pcs:0.11.4-6.el9:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_high_availability:9.0:*:*:*:*:*:*:* | ||
9.2CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_high_availability_eus:9.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.