Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.jenkins-ci.main/jenkins-core
  4. ›
  5. CVE-2014-9634

CVE-2014-9634: Jenkins secure flag not set on session cookies

May 17, 2022 (updated January 30, 2024)

Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

References

  • www.openwall.com/lists/oss-security/2015/01/22/3
  • www.securityfocus.com/bid/72054
  • bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682
  • bugzilla.redhat.com/show_bug.cgi?id=1185148
  • github.com/advisories/GHSA-g7cf-wg27-qw87
  • github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710
  • issues.jenkins-ci.org/browse/JENKINS-25019
  • jenkins.io/changelog-old/
  • nvd.nist.gov/vuln/detail/CVE-2014-9634

Code Behaviors & Features

Detect and mitigate CVE-2014-9634 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.586

Fixed versions

  • 1.586

Solution

Upgrade to version 1.586 or above.

Impact 5.3 MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-254

Source file

maven/org.jenkins-ci.main/jenkins-core/CVE-2014-9634.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:25 +0000.