CVE-2015-3983
published 2015-05-14CVE-2015-3983: The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.10%
79.5th percentile
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pcs | — | — |
| fedora | pacemaker_configuration_system | <= 0.9.137 | — |
| redhat | enterprise_linux_high_availability | — | — |
| redhat | enterprise_linux_high_availability | — | — |
| redhat | enterprise_linux_high_availability_eus | — | — |
| redhat | enterprise_linux_high_availability_eus | — | — |
| redhat | enterprise_linux_resilient_storage | — | — |
| redhat | enterprise_linux_resilient_storage | — | — |
| redhat | enterprise_linux_resilient_storage_eus | — | — |
| redhat | enterprise_linux_resilient_storage_eus | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
pcs: improper web session variable signing
vendor_redhat·2015-05-12·CVSS 6.8
CVE-2015-1848 [MEDIUM] CWE-347 pcs: improper web session variable signing
pcs: improper web session variable signing
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.
It was found that the pcs daemon did not sign cookies containing session data that were sent to clients connecting via the pcsd web UI. A remote attacker could use this flaw to forge cookies and bypass authorization checks, possibly gaining elevated privileges in the pcsd web UI.
Red Hat
pcs: improper web session variable signing
vendor_redhat·2015-05-12·CVSS 6.8
CVE-2015-3983 [MEDIUM] CWE-347 pcs: improper web session variable signing
pcs: improper web session variable signing
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.
It was found that the pcs daemon did not sign cookies containing session data that were sent to clients connecting via the pcsd web UI. A remote attacker could use this flaw to forge cookies and bypass authorization checks, possibly gaining elevated privileges in the pcsd web UI.
Debian
CVE-2015-1848: pcs - The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag fo...
vendor_debian·2015·CVSS 6.8
CVE-2015-1848 [MEDIUM] CVE-2015-1848: pcs - The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag fo...
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2015-3983: pcs - The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly f...
vendor_debian·2015·CVSS 6.8
CVE-2015-3983 [MEDIUM] CVE-2015-3983: pcs - The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly f...
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-wqr4-6q63-33fp: The pcs daemon (pcsd) in PCS 0
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2015-1848 [MEDIUM] GHSA-wqr4-6q63-33fp: The pcs daemon (pcsd) in PCS 0
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.
GHSA
GHSA-vp3g-8qhm-pw5j: The pcs daemon (pcsd) in PCS 0
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2015-3983 [MEDIUM] GHSA-vp3g-8qhm-pw5j: The pcs daemon (pcsd) in PCS 0
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159374.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159412.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0980.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0990.htmlhttp://www.securityfocus.com/bid/74682https://bugzilla.redhat.com/attachment.cgi?id=1009855http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159374.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159412.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0980.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0990.htmlhttp://www.securityfocus.com/bid/74682https://bugzilla.redhat.com/attachment.cgi?id=1009855
2015-05-14
Published