Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLIT from CVE-2015-1848 per ADT2 due to different vulnerability types.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PCS pcs守护进程安全漏洞
Vulnerability Description
PCS是一套利用命令行和Web UI来配置和管理Pacemaker和Corosync(集群软件)的工具。 PCS 0.9.137及之前版本的pcs守护进程(pcsd)中存在安全漏洞,该漏洞源于Set-Cookie头中没有HTTPOnly标志。远程攻击者可通过脚本访问cookie利用该漏洞获取潜在的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A