Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.3 (see CHANGELOG_WUI.md) Fixed a crash when running pcs resource|stonith list Fixed order of resources in sets when listing configuration of constraints. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d420bebe72 2026-06-10 00:54:41.795203+00:00 -------------------------------------------------------------------------------- Name : pcs Product : Fedora 44 Version : 0.12.2 Release : 2.fc44 URL : https://github.com/ClusterLabs/pcs Summary : Pacemaker/Corosync Configuration System Description : pcs is a configuration tool for Corosync and Pacemaker. It permits users to easily view, modify and create high availability clusters based on Pacemaker. This package contains the pcs command-line utility and its server pcsd. -------------------------------------------------------------------------------- Update Information: Updated standalone web UI and HA Cluster Management Cockpit application to pcs- web-ui 0.1.24.3 (see CHANGELOG_WUI.md) Fixed a crash when running pcs resource|stonith list Fixed order of resources in sets when listing configuration of constraints -------------------------------------------------------------------------------- ChangeLog: * Fri May 15 2026 Michal Pospíšil - 0.12.2-2 - Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.24.3 (see CHANGELOG_WUI.md) Resolves: rhbz#2454042 - Fixed a crash when running pcs resource|stonith list Resolves: rhbz#2458608 - Fixed order of resources in sets when listing configuration of constraints Resolves: rhbz#2461143 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2454042 - CVE-2026-4800 pcs: lodash: Arbitrary code execution via untrusted input in template imports [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454042 [ 2 ] Bug #2458608 -pcs resource list produces traceback https://bugzilla.redhat.com/show_bug.cgi?id=2458608 [ 3 ] Bug #2461143 - pcs constraint in default text mode orders resources alphabetically https://bugzilla.redhat.com/show_bug.cgi?id=2461143 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d420bebe72' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Explore the update for Fedora 44 pcs addressing critical security issues including code execution vulnerabilities.. Fedora 44 pcs update security web UI code execution. . Severity: Important. LinuxSecurity.com Team
mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950) SL6 x86_64 mailman-2.1.12-26.el6_9.3.x86_64.rpm mailman-debuginfo-2.1.12-26.el6_9.3.x86_64.rpm i386 mailman-2.1.12-26.el6_9.3.i686.rpm mailman-debuginfo-2.1.12-26.el6_9.3.i686.rpm - Scientific Linux Development Team. Synopsis: Moderate: mailman security update Advisory ID: SLSA-2018:0504-1 Issue Date: 2018-03-13 CVE Numbers: CVE-2018-5950 -- Security Fix(es): * mailman: Cross-site scripting (XSS) vulnerability in web UI (CVE-2018-5950) -- SL6 x86_64 mailman-2.1.12-26.el6_9.3.x86_64.rpm mailman-debuginfo-2.1.12-26.el6_9.3.x86_64.rpm i386 mailman-2.1.12-26.el6_9.3.i686.rpm mailman-debuginfo-2.1.12-26.el6_9.3.i686.rpm - Scientific Linux Development Team . Significant postal service patch for Scientific Linux rectifies XSS vulnerabilities highlighted in SLSA-2018-0504-1.. mailman security, cross-site scripting, SL6 moderate advisory, web UI vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.