First published: Fri Jan 23 2015(Updated: )
Yann Rouillard reports: Jenkins on Tomcat fails to set the secure flag on cookies. External references: <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682</a> <a href="https://issues.jenkins-ci.org/browse/JENKINS-25019">https://issues.jenkins-ci.org/browse/JENKINS-25019</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins LTS | ||
Apache Tomcat |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1185148 has a moderate severity as it affects the security of cookies used by Jenkins on Tomcat.
To fix REDHAT-BUG-1185148, ensure that the secure flag is properly set on cookies in your Jenkins configuration on Tomcat.
REDHAT-BUG-1185148 affects the Jenkins application running on the Tomcat server.
REDHAT-BUG-1185148 introduces potential security risks by not setting the secure flag on cookies, which can lead to cookie theft via man-in-the-middle attacks.
A temporary workaround for REDHAT-BUG-1185148 is to manually configure your Jenkins to enforce the secure flag on cookies until an official patch is released.