cbcvebase.
CVE-2015-3983
published 2015-05-14

CVE-2015-3983: The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to…

PriorityP417medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.10%
79.5th percentile
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianpcs
fedorapacemaker_configuration_system<= 0.9.137
redhatenterprise_linux_high_availability
redhatenterprise_linux_high_availability
redhatenterprise_linux_high_availability_eus
redhatenterprise_linux_high_availability_eus
redhatenterprise_linux_resilient_storage
redhatenterprise_linux_resilient_storage
redhatenterprise_linux_resilient_storage_eus
redhatenterprise_linux_resilient_storage_eus

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.