Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1003004

Опубликовано: 16 янв. 2019
Источник: redhat
CVSS3: 6.2

Описание

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user account may have been deleted in the mean time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10jenkinsWill not fix
Red Hat OpenShift Container Platform 3.2jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.3jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.4jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.5jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.6jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.7jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.9jenkinsWill not fix
Red Hat OpenShift Container Platform 4jenkinsNot affected
Red Hat OpenShift Container Platform 3.11atomic-enterprise-service-catalogFixedRHBA-2019:032620.02.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-384->CWE-613
https://bugzilla.redhat.com/show_bug.cgi?id=1668736jenkins: deleting a user record will does not invalidate existing sessions

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
около 7 лет назад

An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user account may have been deleted in the mean time.

CVSS3: 7.2
debian
около 7 лет назад

An improper authorization vulnerability exists in Jenkins 2.158 and ea ...

CVSS3: 7.2
github
больше 3 лет назад

Improper Authorization in Jenkins Core

CVSS3: 7.2
fstec
около 7 лет назад

Уязвимость сервера автоматизации Jenkins, позволяющая нарушителю повторно использовать регистрационные данные или идентификаторы сеанса для авторизации

6.2 Medium

CVSS3