{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "failure to set secure flag on cookies",
    "tracking": {
      "current_release_date": "2026-08-11T14:03:26+00:00",
      "generator": {
        "date": "2026-08-11T14:03:26+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2014-9634",
      "initial_release_date": "2014-11-15T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:03:26+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 2.2.0",
            "product": {
              "name": "OpenShift Container Platform 2.2.0",
              "product_id": "openshift-enterprise-2.2",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:2"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jenkins",
            "product": {
              "name": "jenkins",
              "product_id": "jenkins",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jenkins"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jenkins",
            "product": {
              "name": "jenkins",
              "product_id": "jenkins.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jenkins?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins as a component of OpenShift Container Platform 2.2.0",
          "product_id": "openshift-enterprise-2.2:jenkins"
        },
        "product_reference": "jenkins",
        "relates_to_product_reference": "openshift-enterprise-2.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 2.2.0",
          "product_id": "openshift-enterprise-2.2:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-enterprise-2.2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-9634",
      "discovery_date": "2014-11-28T00:00:00+00:00",
      "notes": [
        {
          "category": "other",
          "text": "This issue affects the versions of Jenkins as shipped with Red Hat OpenShift Enterprise 2. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "openshift-enterprise-2.2:jenkins",
          "openshift-enterprise-2.2:jenkins.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-9634"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-9634"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-9634"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "openshift-enterprise-2.2:jenkins",
            "openshift-enterprise-2.2:jenkins.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
            "baseScore": 4.3
          },
          "products": [
            "openshift-enterprise-2.2:jenkins",
            "openshift-enterprise-2.2:jenkins.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low",
          "product_ids": [
            "openshift-enterprise-2.2:jenkins",
            "openshift-enterprise-2.2:jenkins.src"
          ]
        }
      ],
      "title": "failure to set secure flag on cookies"
    }
  ]
}