CVE-2023-2319 Details
Description
It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via erratum RHSA-2023:1591. The CVE-2023-2319 was assigned to that Red Hat specific security regression in Red Hat Enterprise Linux 9.2.
A security regression vulnerability has been identified in the PCS package of Red Hat Enterprise Linux 9.2. This issue arises because an update for the PCS package in the 9.2 release failed to include a crucial fix for a Webpack vulnerability (CVE-2023-28154) that had been addressed in the 9.1 release. As a result, users who update to Red Hat Enterprise Linux 9.2 may encounter this vulnerability, even though it was properly fixed in the previous version.
Users can apply the available update for this vulnerability by referring to the Red Hat Enterprise Linux 9.2 advisory RHSA-2023:2652.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2023:2652 | CVE | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2023-2319 | CVE | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2190092 | CVE | Issue Tracking |
| https://access.redhat.com/errata/RHSA-2023:2652 | [email protected] | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2023-2319 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2190092 | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| clusterlabs pcs | 0.11.4-6.el9 |
CPE
Remediation
| |
| redhat enterprise linux high availability | 9.0 |
CPE
Remediation
| |
| redhat enterprise linux high availability eus | 9.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 22, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 26, 2023 | Initial Analysis | [email protected] |