Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-742j-jcfr-23w3

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Insufficient Session Expiration in Jenkins

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.164.1

2.164.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.165, <= 2.171

2.172

EPSS

Процентиль: 65%
0.00493
Низкий

8.1 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5
redhat
почти 7 лет назад

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.

CVSS3: 8.1
nvd
почти 7 лет назад

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.

CVSS3: 8.1
debian
почти 7 лет назад

Users who cached their CLI authentication before Jenkins was updated t ...

EPSS

Процентиль: 65%
0.00493
Низкий

8.1 High

CVSS3

Дефекты

CWE-613