Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6rh5-23hx-j452

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Improper Authorization in Jenkins Core

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.150.2

2.150.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.151, < 2.159

2.159

EPSS

Процентиль: 83%
0.01946
Низкий

7.2 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 6.6
redhat
около 7 лет назад

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.

CVSS3: 7.2
nvd
около 7 лет назад

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.

CVSS3: 7.2
debian
около 7 лет назад

An improper authorization vulnerability exists in Jenkins 2.158 and ea ...

CVSS3: 7.2
fstec
около 7 лет назад

Уязвимость компонента TokenBasedRememberMeServices2.java (core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java) сервера автоматизации Jenkins, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 83%
0.01946
Низкий

7.2 High

CVSS3

Дефекты

CWE-285