Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2015/01/22/3 | third party advisory mailing list |
https://issues.jenkins-ci.org/browse/JENKINS-25019 | issue tracking vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1185151 | issue tracking vdb entry third party advisory |
https://jenkins.io/changelog-old/ | release notes vendor advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682 | third party advisory |
https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710 | third party advisory patch |
http://www.securityfocus.com/bid/72054 | vdb entry third party advisory |