Описание
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.532.1 (включая)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Конфигурация 2Версия до 1.550 (включая)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.02061
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
ubuntu
почти 12 лет назад
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
redhat
больше 12 лет назад
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
debian
почти 12 лет назад
Session fixation vulnerability in Jenkins before 1.551 and LTS before ...
EPSS
Процентиль: 80%
0.02061
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-287