Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9635

Опубликовано: 12 сент. 2017
Источник: debian
EPSS Низкий

Описание

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jenkinsfixed1.565.3-3package

EPSS

Процентиль: 52%
0.00288
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 8 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

redhat
больше 10 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

CVSS3: 5.3
nvd
почти 8 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

CVSS3: 5.3
github
около 3 лет назад

Jenkins HttpOnly flag not Set for session cookies

EPSS

Процентиль: 52%
0.00288
Низкий