Description
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2009-1008 Vulnerability (CVE-2009-1008)
WordPress Plugin PHP Event Calendar for WordPress Arbitrary File Upload (1.6)
Dolibarr CVE-2023-38886 Vulnerability (CVE-2023-38886)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Unspecified Vulnerability (3.1.6)
phpMyFAQ Insufficient Session Expiration Vulnerability (CVE-2023-5865)