PT-2018-15224 · Cloudbees+1 · Jenkins

Published

2018-08-23

·

Updated

2022-05-14

·

CVE-2018-1999045

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins versions prior to 2.137 Jenkins versions prior to 2.121.2
Description A vulnerability exists due to improper authentication, allowing attackers with a valid cookie to remain logged in even if the feature is disabled. This issue is related to the SecurityRealm.java and TokenBasedRememberMeServices2.java files.
Recommendations For versions prior to 2.137, update to a version that includes the fix for this issue. For versions prior to 2.121.2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the SecurityRealm.java and TokenBasedRememberMeServices2.java files until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1999045
GHSA-Q4CQ-R7HG-PXQQ

Affected Products

Jenkins