Red Hat Bugzilla – Bug 1185151
CVE-2014-9635 Jenkins on Tomcat: failure to set httponly flag on cookies
Last modified: 2016-02-15 05:28:47 EST
Yann Rouillard reports: Jenkins on Tomcat fails to set the httponly flag on cookies. External references: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682 https://issues.jenkins-ci.org/browse/JENKINS-25019
Created jenkins tracking bugs for this issue: Affects: fedora-21 [bug 1185152]
Acknowledgements: Red Hat would like to thank Yann Rouillard for reporting this issue.
Statement: This issue affects the versions of Jenkins as shipped with Red Hat OpenShift Enterprise 2. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.