cbcvebase.
CVE-2015-1848
published 2015-05-14

CVE-2015-1848: The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to…

PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.42%
82.3th percentile
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianpcs
fedorapacemaker_configuration_system<= 0.9.137
redhatenterprise_linux_high_availability
redhatenterprise_linux_high_availability
redhatenterprise_linux_high_availability_eus
redhatenterprise_linux_high_availability_eus
redhatenterprise_linux_resilient_storage
redhatenterprise_linux_resilient_storage
redhatenterprise_linux_resilient_storage_eus
redhatenterprise_linux_resilient_storage_eus

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.