Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Jan 3, 2020 | Sep 25, 2019 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Sep 26, 2019 | Sep 25, 2019 |
| Jenkins 2019 09 25 | — | Upgrade Jenkins LTS to version 2.176.4Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.197Upgrade Jenkins to the latest version | Oct 8, 2019 | Sep 25, 2019 |
| Redhat Openshift | — | Upgrade jenkins | Dec 29, 2020 | Sep 25, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub