← Vulnerability feed

Vulnerability record · CVE-2015-1848 · published 14 May 2015

CVE-2015-1848: Fedora pacemaker configuration system vulnerability

Fedora · Pacemaker Configuration System

The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.

6.8 CVSS 2.0 Medium EPSS 2.4% · top 16.5% CWE-310 · CWE-310
6.8CVSS 2.0 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
14References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1848 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-2319Clusterlabs pcs vulnerabilityIt was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix…EPSS 0.97%8.8CVE-2021-44142Samba vfs_fruit heap out-of-bounds read/write enables code executionSamba's vfs_fruit module mishandles extended file attributes (xattr), allowing out-of-bounds heap reads and writes when specially crafted EAs are pro…EPSS 73%analysed8.1CVE-2020-25717Samba improper input validation vulnerabilityA flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalat…EPSS 1.6%7.5CVE-2016-7797Clusterlabs pacemaker vulnerabilityPacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthent…EPSS 3.3%7.5CVE-2015-1867Redhat enterprise linux high availability permissions and access controls vulnerabilityPacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.EPSS 3.0%5.9CVE-2016-2124Samba improper authentication vulnerabilityA flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w…EPSS 1.8%4.3CVE-2015-3983Fedora pacemaker configuration system vulnerabilityThe pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attacker…EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2015-1848), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.