Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1003049

Опубликовано: 10 апр. 2019
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
Версия до 2.164.1 (включая)
Конфигурация 2
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:*
Версия до 2.171 (включая)
Конфигурация 3
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00493
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 5
redhat
почти 7 лет назад

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.

CVSS3: 8.1
debian
почти 7 лет назад

Users who cached their CLI authentication before Jenkins was updated t ...

CVSS3: 8.1
github
больше 3 лет назад

Insufficient Session Expiration in Jenkins

EPSS

Процентиль: 65%
0.00493
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-613