fedora pacemaker-configuration-system CVE-2015-1848 in Fedora and Red Hat Products
Published on May 14, 2015

product logo product logo
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.

Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2015-1848

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2015-1848 are published in these products:

 
 
 
 
 

Exploit Probability

EPSS
1.21%
Percentile
78.72%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.