6.8
CVE-2015-1848
- EPSS 1.21%
- Veröffentlicht 14.05.2015 14:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fedora ≫ Pacemaker Configuration System Version <= 0.9.137
Redhat ≫ Enterprise Linux High Availability Version6.0
Redhat ≫ Enterprise Linux High Availability Version7.0
Redhat ≫ Enterprise Linux High Availability Eus Version6.6.z
Redhat ≫ Enterprise Linux High Availability Eus Version7.1
Redhat ≫ Enterprise Linux Resilient Storage Version6.0
Redhat ≫ Enterprise Linux Resilient Storage Version7.0
Redhat ≫ Enterprise Linux Resilient Storage Eus Version6.6.z
Redhat ≫ Enterprise Linux Resilient Storage Eus Version7.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.21% | 0.781 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|