6.8
CVE-2015-1848
- EPSS 1.21%
- Published 14.05.2015 14:59:07
- Last modified 12.04.2025 10:46:40
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.
Data is provided by the National Vulnerability Database (NVD)
Fedora ≫ Pacemaker Configuration System Version <= 0.9.137
Redhat ≫ Enterprise Linux High Availability Version6.0
Redhat ≫ Enterprise Linux High Availability Version7.0
Redhat ≫ Enterprise Linux High Availability Eus Version6.6.z
Redhat ≫ Enterprise Linux High Availability Eus Version7.1
Redhat ≫ Enterprise Linux Resilient Storage Version6.0
Redhat ≫ Enterprise Linux Resilient Storage Version7.0
Redhat ≫ Enterprise Linux Resilient Storage Eus Version6.6.z
Redhat ≫ Enterprise Linux Resilient Storage Eus Version7.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.21% | 0.781 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|