ALAS2-2025-2853


Amazon Linux 2 Security Advisory: ALAS2-2025-2853
Advisory Released Date: 2025-05-13
Advisory Updated Date: 2025-05-13
Severity: Medium

Issue Overview:

Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the X-Forwarded-Host (XFH) header. When making a request to a method with redirect applied, it is possible to trigger an Open Redirect Attack by inserting an arbitrary address into this header. If used for caching purposes, such as with servers like Nginx, or as a reverse proxy, without handling the X-Forwarded-Host header, attackers can potentially exploit Cache Poisoning or Routing-based SSRF. (CVE-2024-21510)


Affected Packages:

pcs


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update pcs to update your system.

New Packages:
aarch64:
    pcs-0.9.169-3.amzn2.3.0.5.aarch64
    pcs-snmp-0.9.169-3.amzn2.3.0.5.aarch64
    pcs-debuginfo-0.9.169-3.amzn2.3.0.5.aarch64

i686:
    pcs-0.9.169-3.amzn2.3.0.5.i686
    pcs-snmp-0.9.169-3.amzn2.3.0.5.i686
    pcs-debuginfo-0.9.169-3.amzn2.3.0.5.i686

src:
    pcs-0.9.169-3.amzn2.3.0.5.src

x86_64:
    pcs-0.9.169-3.amzn2.3.0.5.x86_64
    pcs-snmp-0.9.169-3.amzn2.3.0.5.x86_64
    pcs-debuginfo-0.9.169-3.amzn2.3.0.5.x86_64