Description
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2796 Vulnerability (CVE-2019-2796)
Moodle Credentials Management Errors Vulnerability (CVE-2014-7845)
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-16107)
TYPO3 Other Vulnerability (CVE-2012-3530)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2609)