Jenkins secure flag not set on session cookies
Research is free — Hunters explains how the bug works, the root-cause code pattern, how the fix addresses it, and how to test whether a target is affected, in chat. Investigate & write exploit is a paid run — the engine reads the advisory and fix commits, then builds and validates a working proof-of-concept exploit with reproduction steps.
Affected versions
0 → fixed in 1.586
Details
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.
The fix
No fix commit could be resolved for this advisory (it may reference an issue tracker or a non-GitHub patch). See the references below.
References
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2014-9634
- WEBhttps://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710
- WEBhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=1185148
- WEBhttps://issues.jenkins-ci.org/browse/JENKINS-25019
- WEBhttps://jenkins.io/changelog-old
- WEBhttp://www.openwall.com/lists/oss-security/2015/01/22/3
- WEBhttp://www.securityfocus.com/bid/72054