CVE-2014-9634: Medium severity Jenkins Jenkins vulnerability
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.
Other sources
Yann Rouillard reports:
Jenkins on Tomcat fails to set the secure flag on cookies.
External references: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682 https://issues.jenkins-ci.org/browse/JENKINS-25019
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9634?
CVE-2014-9634 is considered a medium severity vulnerability due to its potential for cookie interception.
How do I fix CVE-2014-9634?
To fix CVE-2014-9634, upgrade Jenkins to version 1.586 or later when running on Tomcat 7.0.41 or later.
Who discovered CVE-2014-9634?
CVE-2014-9634 was reported by security researcher Yann Rouillard.
What systems are affected by CVE-2014-9634?
CVE-2014-9634 affects Jenkins versions before 1.586 when run on Tomcat version 7.0.41 or later.
What is the nature of the vulnerability CVE-2014-9634?
CVE-2014-9634 involves the lack of a secure flag on session cookies, making them susceptible to interception.