Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f6w-fhmr-j8hq

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Jenkins HttpOnly flag not Set for session cookies

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.586

1.586

EPSS

Процентиль: 52%
0.00288
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 8 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

redhat
почти 11 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

CVSS3: 5.3
nvd
почти 8 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

CVSS3: 5.3
debian
почти 8 лет назад

Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie he ...

EPSS

Процентиль: 52%
0.00288
Низкий

5.3 Medium

CVSS3