Description
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
Published: 2019-04-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-2908 Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
Github GHSA Github GHSA GHSA-742j-jcfr-23w3 Insufficient Session Expiration in Jenkins
History

No history.

Subscriptions

Jenkins Jenkins
Oracle Communications Cloud Native Core Automated Test Suite
Redhat Openshift Openshift Container Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published:

Updated: 2024-08-05T03:07:18.205Z

Reserved: 2019-04-10T00:00:00.000Z

Link: CVE-2019-1003049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-10T21:29:01.480

Modified: 2024-11-21T04:17:48.607

Link: CVE-2019-1003049

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-04-10T00:00:00Z

Links: CVE-2019-1003049 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses