QID 997482
Date Published: 2024-02-26
QID 997482: Java (Maven) Security Update for org.jenkins-ci.main:jenkins-core (GHSA-g7cf-wg27-qw87)
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-g7cf-wg27-qw87 for updates and patch information.
Vendor References
- GHSA-g7cf-wg27-qw87 -
github.com/advisories/GHSA-g7cf-wg27-qw87
CVEs related to QID 997482
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g7cf-wg27-qw87 | org.jenkins-ci.main:jenkins-core |
|