6.8
CVE-2015-1848
- EPSS 1.21%
- Veröffentlicht 14.05.2015 14:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedora ≫ Pacemaker Configuration System Version <= 0.9.137
Redhat ≫ Enterprise Linux High Availability Version6.0
Redhat ≫ Enterprise Linux High Availability Version7.0
Redhat ≫ Enterprise Linux High Availability Eus Version6.6.z
Redhat ≫ Enterprise Linux High Availability Eus Version7.1
Redhat ≫ Enterprise Linux Resilient Storage Version6.0
Redhat ≫ Enterprise Linux Resilient Storage Version7.0
Redhat ≫ Enterprise Linux Resilient Storage Eus Version6.6.z
Redhat ≫ Enterprise Linux Resilient Storage Eus Version7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.21% | 0.781 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|