Description
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.
Remediation
References
https://jenkins.io/changelog-old/
https://issues.jenkins-ci.org/browse/JENKINS-25019
https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710
https://bugzilla.redhat.com/show_bug.cgi?id=1185148
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682
http://www.securityfocus.com/bid/72054
http://www.openwall.com/lists/oss-security/2015/01/22/3
Related Vulnerabilities
CVE-2021-32850 Vulnerability in npm package @claviska/jquery-minicolors
CVE-2023-35167 Vulnerability in npm package remult
CVE-2023-4863 Vulnerability in npm package electron
CVE-2022-45380 Vulnerability in maven package org.jenkins-ci.plugins:junit
CVE-2020-4077 Vulnerability in maven package org.webjars.npm:electron