Описание
A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a new user account.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.138.1 (включая)Версия до 2.145 (включая)
Одно из
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*
EPSS
Процентиль: 22%
0.00073
Низкий
5.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-384
Связанные уязвимости
CVSS3: 5.4
redhat
больше 7 лет назад
A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a new user account.
CVSS3: 5.4
debian
около 7 лет назад
A session fixation vulnerability exists in Jenkins 2.145 and earlier, ...
EPSS
Процентиль: 22%
0.00073
Низкий
5.4 Medium
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-384