Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wr9-2xc6-jmg5

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Session fixation vulnerability in Jenkins

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login. This allows attackers to use social engineering techniques to gain administrator access to Jenkins.

This vulnerability was introduced in Jenkins 2.266 and LTS 2.277.1.

Jenkins 2.300, LTS 2.289.2 invalidates the previous session on login.

In case of problems, administrators can choose a different implementation by setting the Java system property hudson.security.SecurityRealm.sessionFixationProtectionMode to 2, or disable the fix entirely by setting that system property to 0.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.292, <= 2.299

2.300

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.289.1

2.289.2

EPSS

Процентиль: 50%
0.00273
Низкий

7.5 High

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 7.5
redhat
больше 4 лет назад

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

CVSS3: 7.5
nvd
больше 4 лет назад

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

CVSS3: 7.5
debian
больше 4 лет назад

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate ...

EPSS

Процентиль: 50%
0.00273
Низкий

7.5 High

CVSS3

Дефекты

CWE-384