Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2019-04-10T20:12:29

Updated: 2024-08-05T03:07:18.205Z

Reserved: 2019-04-10T00:00:00

Link: CVE-2019-1003049

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-04-10T21:29:01.480

Modified: 2024-11-21T04:17:48.607

Link: CVE-2019-1003049

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-04-10T00:00:00Z

Links: CVE-2019-1003049 - Bugzilla