REDHAT-BUG-1185148: Low severity jenkins lts vulnerability
Yann Rouillard reports:
Jenkins on Tomcat fails to set the secure flag on cookies.
External references: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682 https://issues.jenkins-ci.org/browse/JENKINS-25019
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1185148?
REDHAT-BUG-1185148 has a moderate severity as it affects the security of cookies used by Jenkins on Tomcat.
How do I fix REDHAT-BUG-1185148?
To fix REDHAT-BUG-1185148, ensure that the secure flag is properly set on cookies in your Jenkins configuration on Tomcat.
What types of software are affected by REDHAT-BUG-1185148?
REDHAT-BUG-1185148 affects the Jenkins application running on the Tomcat server.
What vulnerabilities does REDHAT-BUG-1185148 introduce?
REDHAT-BUG-1185148 introduces potential security risks by not setting the secure flag on cookies, which can lead to cookie theft via man-in-the-middle attacks.
Is there a workaround for REDHAT-BUG-1185148?
A temporary workaround for REDHAT-BUG-1185148 is to manually configure your Jenkins to enforce the secure flag on cookies until an official patch is released.