A improper authentication vulnerability exists in Jenkins 2.137 and earlier, 2.121.2 and earlier in SecurityRealm.java, TokenBasedRememberMeServices2.java that allows attackers with a valid cookie to remain logged in even if that feature is disabled.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-08-23T18:00:00Z
Updated: 2024-09-17T00:56:20.100Z
Reserved: 2018-08-23T00:00:00Z
Link: CVE-2018-1999045
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-08-23T18:29:00.843
Modified: 2024-11-21T03:57:07.907
Link: CVE-2018-1999045
Redhat