An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS00N3djLXA1Y3Atdzdwd84AAq6Q

Moderate EPSS: 0.71436% (0.98675 Percentile) EPSS:

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins

Affected Packages Affected Versions Fixed Versions
maven:org.jenkins-ci.main:jenkins-core >= 2.177, <= 2.196, <= 2.176.3 2.197, 2.176.4

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.

References: