CVE-2015-1848
Pacemaker Configuration System < 0.9.137 - Cookie Secure Flag Not Set
Title source: llmDescription
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.
References (7)
Core 7
Core References
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0990.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159374.html
Exploit, Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/attachment.cgi?id=1009855
Third Party Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0980.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159412.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159401.html
Third Party Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/74623
Scores
EPSS
0.0242
EPSS Percentile
82.5%
Details
CWE
CWE-310
Status
published
Products (9)
fedora/pacemaker_configuration_system
< 0.9.137
redhat/enterprise_linux_high_availability
6.0
redhat/enterprise_linux_high_availability
7.0
redhat/enterprise_linux_high_availability_eus
6.6.z
redhat/enterprise_linux_high_availability_eus
7.1
redhat/enterprise_linux_resilient_storage
6.0
redhat/enterprise_linux_resilient_storage
7.0
redhat/enterprise_linux_resilient_storage_eus
6.6.z
redhat/enterprise_linux_resilient_storage_eus
7.1
Published
May 14, 2015
Tracked Since
Feb 18, 2026