CVE-2019-10405: Jenkins <=2.196 - Cookie Exposure

CVE-2019-10405: Jenkins <=2.196 - Cookie Exposure-渗透云记 - 专注于网络安全与技术分享
CVE-2019-10405: Jenkins <=2.196 - Cookie Exposure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2019-10405: Jenkins <=2.196 – Cookie Exposure

漏洞描述

Jenkins through 2.196, LTS 2.176.3 and earlier prints the value of the cookie on the /whoAmI/ URL despite it being marked HttpOnly, thus making it possible to steal cookie-based authentication credentials if the URL is exposed or accessed via another cross-site scripting issue.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享