← Back to CVE List

CVE-2014-9635

Published: 2017-09-12T14:29Z
Last Modified: 2024-11-21T02:21Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt