Description
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2015-1959 | The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag. |
References
History
No history.
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T04:54:16.367Z
Reserved: 2015-02-17T00:00:00.000Z
Link: CVE-2015-1848
No data.
Status : Modified
Published: 2015-05-14T14:59:07.897
Modified: 2026-05-06T22:30:45.220
Link: CVE-2015-1848
OpenCVE Enrichment
No data.
EUVD