CVE-2015-3983

CWE-310CWE-3477 documents6 sources
Severity
4.3MEDIUM
EPSS
0.6%
top 30.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateMay 17

Description

The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-vp3g-8qhm-pw5j: The pcs daemon (pcsd) in PCS 02022-05-17
CVEList
CVE-2015-3983: The pcs daemon (pcsd) in PCS 02015-05-14

📋Vendor Advisories

3
Red Hat
pcs: improper web session variable signing2015-05-12
Red Hat
pcs: improper web session variable signing2015-05-12
Debian
CVE-2015-3983: pcs - The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly f...2015

💬Community

1
Bugzilla
CVE-2015-1848 CVE-2015-3983 pcs: improper web session variable signing2015-04-01