CVE-2014-9635
medium
CVSS v3
5.3
CVSS v2
5.0
VIR risk
5.3
Description
Jenkins HttpOnly flag not Set for session cookies
Predictions
Exploit likelihood
63%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://jenkins.io/changelog-old/
Vendor advisory: secalert@redhat.com — https://issues.jenkins-ci.org/browse/JENKINS-25019
Vendor advisory: secalert@redhat.com — https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.jenkins-ci.main:jenkins-core | <1.586 | 1.586 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| jenkins | jenkins | {"endIncluding":"1.585"} | |
| apache | tomcat | 7.0.41 | |
| apache | tomcat | 7.0.42 | |
| apache | tomcat | 7.0.43 | |
| apache | tomcat | 7.0.44 | |
| apache | tomcat | 7.0.45 | |
| apache | tomcat | 7.0.46 | |
| apache | tomcat | 7.0.47 | |
| apache | tomcat | 7.0.48 | |
| apache | tomcat | 7.0.49 | |
| apache | tomcat | 7.0.50 | |
| apache | tomcat | 7.0.51 | |
| apache | tomcat | 7.0.54 | |
| apache | tomcat | 7.0.55 | |
| apache | tomcat | 7.0.56 | |
| apache | tomcat | 7.0.57 | |
| apache | tomcat | 7.0.58 | |
| apache | tomcat | 7.0.59 | |
| apache | tomcat | 7.0.60 | |
| apache | tomcat | 7.0.61 | |
| apache | tomcat | 7.0.62 | |
| apache | tomcat | 7.0.63 | |
| apache | tomcat | 7.0.64 | |
| apache | tomcat | 7.0.65 | |
| apache | tomcat | 7.0.66 | |
| apache | tomcat | 7.0.67 | |
| apache | tomcat | 7.0.68 | |
| apache | tomcat | 7.0.69 | |
| apache | tomcat | 7.0.70 | |
| apache | tomcat | 7.0.71 | |
| apache | tomcat | 7.0.72 | |
| apache | tomcat | 7.0.73 | |
| apache | tomcat | 7.0.74 | |
| apache | tomcat | 7.0.75 | |
| apache | tomcat | 7.0.76 | |
| apache | tomcat | 7.0.77 | |
| apache | tomcat | 7.0.78 | |
| apache | tomcat | 7.0.79 | |
| apache | tomcat | 7.0.80 | |
| apache | tomcat | 7.0.81 | |
References
- http://www.openwall.com/lists/oss-security/2015/01/22/3
- http://www.securityfocus.com/bid/72054
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682
- https://bugzilla.redhat.com/show_bug.cgi?id=1185151
- https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710
- https://issues.jenkins-ci.org/browse/JENKINS-25019
- https://jenkins.io/changelog-old/
- https://nvd.nist.gov/vuln/detail/CVE-2014-9635
- https://jenkins.io/changelog-old
CWEs
CWE-254
Verify integrity in audit chain (admin only). AS-IS.