Описание
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-infra-legacy/trusty | DNE | |
| lucid | DNE | |
| precise | ignored | end of life |
| precise/esm | DNE | precise was needed |
| quantal | ignored | end of life |
| saucy | ignored | end of life |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | needed |
Показывать по
10
EPSS
Процентиль: 34%
0.00138
Низкий
6.8 Medium
CVSS2
Связанные уязвимости
redhat
почти 12 лет назад
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
nvd
больше 11 лет назад
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
debian
больше 11 лет назад
Session fixation vulnerability in Jenkins before 1.551 and LTS before ...
EPSS
Процентиль: 34%
0.00138
Низкий
6.8 Medium
CVSS2