Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T23:16:51Z",
"nvd_published_at": "2017-09-12T14:29:00Z",
"severity": "MODERATE"
}