Mar 8, 2023, xCAT announced the following security advisory: 
https://github.com/xcat2/xcat-core/security/advisories/GHSA-hpxg-7428-6jvv

Advisory 
CVEs<https://xcat-docs.readthedocs.io/en/latest/security/2023/20230308_xcat.html#advisory-cves>

  *   CVE-2023-27486 - Insufficient authorization validation between zones when 
xCAT zones are enabled (Severity: High)

Please see the security bulletin above for patch, upgrade, or suggested work 
around information.

Action<https://xcat-docs.readthedocs.io/en/latest/security/2023/20230308_xcat.html#action>

The issue described in CVE-2023-27486 only impacts users making use of the 
optional xCAT zones feature. xCAT zones are not enabled by default. Users 
making use of xCAT zones should upgrade to xCAT 2.16.5 or newer. Users that do 
not use xCAT zones are not impacted and do not need to upgrade.
_______________________________________________
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/xcat-user

Reply via email to