CVE-2014-9634
Estado: ModificadaMedia (5.3)—
Jenkins en versiones anteriores a la 1.586 no establece el indicador "secure" cuando se ejecuta en Tomcat 7.0.41 o posterior, lo que facilita que los atacantes remotos capturen cookies interceptando su transmisión en una sesión HTML.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.72%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 10/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-254
Referencias
- http://www.openwall.com/lists/oss-security/2015/01/22/3
- http://www.securityfocus.com/bid/72054
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682
- https://bugzilla.redhat.com/show_bug.cgi?id=1185148
- https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710
- https://issues.jenkins-ci.org/browse/JENKINS-25019
- https://jenkins.io/changelog-old/
- http://www.openwall.com/lists/oss-security/2015/01/22/3
- http://www.securityfocus.com/bid/72054
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682
- https://bugzilla.redhat.com/show_bug.cgi?id=1185148
- https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710
- https://issues.jenkins-ci.org/browse/JENKINS-25019
- https://jenkins.io/changelog-old/
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-9634",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2017-09-12T14:29:00.253",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2015/01/22/3",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.securityfocus.com/bid/72054",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1185148",
"tags": [
"Issue Tracking",
"Third Party Advisory",
"VDB Entry"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://issues.jenkins-ci.org/browse/JENKINS-25019",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://jenkins.io/changelog-old/",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2015/01/22/3",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/72054",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=769682",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1185148",
"tags": [
"Issue Tracking",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/jenkinsci/jenkins/commit/582128b9ac179a788d43c1478be8a5224dc19710",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://issues.jenkins-ci.org/browse/JENKINS-25019",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://jenkins.io/changelog-old/",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-254"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session."
},
{
"lang": "es",
"value": "Jenkins en versiones anteriores a la 1.586 no establece el indicador \"secure\" cuando se ejecuta en Tomcat 7.0.41 o posterior, lo que facilita que los atacantes remotos capturen cookies interceptando su transmisión en una sesión HTML."
}
],
"lastModified": "2026-06-17T00:18:41.087",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1F11E15-FD3D-48AC-9BEA-4E2730551F48",
"versionEndIncluding": "1.585"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.41:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DA8A7333-B4C3-4876-AE01-62F2FD315504"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.42:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "92993E23-D805-407B-8B87-11CEEE8B212F"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.43:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7A11BD74-305C-41E2-95B1-5008EEF5FA5F"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.44:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "595442D0-9DB7-475A-AE30-8535B70E122E"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.45:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4B0BA92A-0BD3-4CE4-9465-95E949104BAC"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.46:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6F944B72-B9EB-4EB8-AEA3-E0D7ADBE1305"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.47:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6AA28D3A-3EE5-4F90-B8F5-4943F7607DA6"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.48:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BFD3EB84-2ED2-49D4-8BC9-6398C2E46F0A"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.49:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DEDF6E1A-0DD6-42AB-9510-F6F4B6002C91"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.50:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C947E549-2459-4AFB-84A7-36BDA30B5F29"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.51:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "67A0EA46-5AEA-4D0A-B89E-6560FA10EC08"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.54:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F8E9453E-BC9B-4F77-85FA-BA15AC55C245"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.55:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A7EF0518-73F9-47DB-8946-A8334936BEFF"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.56:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "95AA8778-7833-4572-A71B-5FD89938CE94"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.57:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "242E47CE-EF69-4F8F-AB40-5AF2811674CE"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.58:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A225D4F7-174E-47C3-8390-C6FA28DB5A9A"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.59:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CDA1555C-E55A-4E14-B786-BFEE3F09220B"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.60:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6BAC42AE-B82A-4ABF-9519-B2D97D925707"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.61:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F8075E9A-DA7F-4A0B-8B4D-0CD951369111"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.62:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "335A5320-6086-4B45-9903-82F6F92A584F"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.63:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "46B33408-C2E2-4E7C-9334-6AB98F13468C"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.64:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9F036676-9EFB-4A92-828E-A38905D594E2"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.65:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E9728EE8-6029-4DF3-942E-E4ACC09111A3"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.66:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "62DBB843-288C-4060-8777-6CDCF1860D29"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.67:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "34E7DAC8-8419-45D1-A28F-14CF2FE1B6EE"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.68:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "89B87EB5-4902-4C2A-878A-45185F7D0FA1"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.69:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C0596E6C-9ACE-4106-A2FF-BED7967C323F"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.70:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8F7158DC-966B-4508-8600-40E3E9D3D0DF"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.71:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A190FE0D-86C1-49EE-BDAE-5879C32BDC92"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.72:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CA20F45F-01A2-43DD-9731-DFF54E31719F"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.73:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3C7A728B-59DB-4EDE-8929-C91F4C410902"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.74:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "26889291-3280-4524-8F4A-9B22FF4600C8"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.75:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6E4CAEBD-0F38-4892-9D0B-9D7392E0BCC3"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.76:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "61C4DA00-E47C-47BE-856C-7E0D4B0F9DAA"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.77:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "41FF234B-A9AD-4C51-8E9E-939DC8ECB64A"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.78:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4FA0E2FD-84FB-4691-B4B5-12A381CB091E"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.79:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "69CC7A75-8EA2-4F62-AF84-CE60C76F9F7C"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.80:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4CA59311-0095-49D7-BDF2-E72F847F3F09"
},
{
"criteria": "cpe:2.3:a:apache:tomcat:7.0.81:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A1E06587-2543-47A9-9E02-4BE7B0190065"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "secalert@redhat.com"
}