Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2015/01/22/3 | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1185148 | issue tracking vdb entry third party advisory |
https://jenkins.io/changelog-old/ | release notes vendor advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682 | third party advisory |
https://issues.jenkins-ci.org/browse/JENKINS-25019 | issue tracking vendor advisory |
https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710 | third party advisory patch |
http://www.securityfocus.com/bid/72054 | vdb entry third party advisory |