PT-2015-5470 · Pcs+2 · Pcs+2

Tomas Jelinek

·

Published

2015-05-12

·

Updated

2023-02-12

·

CVE-2015-1848

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PCS versions 0.9.137 and earlier
Description The issue concerns the pcs daemon (pcsd) in PCS, where it fails to set the secure flag for a cookie in an https session. This oversight makes it easier for remote attackers to capture the cookie by intercepting its transmission within an http session.
Recommendations For versions 0.9.137 and earlier, consider updating to a version that sets the secure flag for cookies in https sessions to prevent interception. As a temporary workaround, restrict access to sensitive operations that rely on the secure transmission of cookies until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CESA-2015_0980
CESA-2015_0990
CVE-2015-1848
RHSA-2015:0980
RHSA-2015:0990
RHSA-2015_0980
RHSA-2015_0990

Affected Products

Centos
Pcs
Red Hat