Scans showing low vulnerability for our Jenkins instance

19 views
Skip to first unread message

s.p...@gmail.com

unread,
Dec 1, 2022, 11:38:53 AM12/1/22
to Jenkins Users
Hi, 

Jenkins is installed on windows server. Our web scans show three low findings .

1) cookie not marked as HttpOnly 
2) [Possible] Cross-site Request Forgery
3) Missing X-frame-options header.

Installed Missing X-frame plugin and the set the option as SAMEORIGIN but the scans still shows as low finding. For the other two , I'm not able to find any resolution in google search. Appreciate any inputs on this. Thanks in Advance.
Reply all
Reply to author
Forward
0 new messages