Impact
In Jenkins, a session fixation flaw allows an attacker who can deliver content from the same origin as the Jenkins instance to set a known session cookie in the victim’s browser. When the victim later authenticates using the "remember me" cookie, the pre‑existing session cookie is reused, giving the attacker a valid Jenkins session with the victim’s privileges. This vulnerability enables a remote attacker to obtain full access to the victim’s account and all data or resources that account can reach.
Affected Systems
The Jenkins Project product "Jenkins" is affected. All releases up to and including 2.579 and the LTS 2.568.2 and earlier are vulnerable. Versions 2.580+, LTS 2.568.3+, and later releases contain the fix and are not affected.
Risk and Exploitability
The vulnerability has a CVSS score of 7.3, indicating moderate‑to‑high severity. The EPSS score of < 1% reflects a relatively low probability of exploitation in the wild, though the potential for complete account takeover gives it a high‑risk character. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the attacker can serve content from the same domain or a sub‑domain of the Jenkins instance to set a session cookie, a scenario that is feasible when sub‑domain takeover or web‑root control is available.
OpenCVE Enrichment