PT-2019-1544 · Red Hat+2 · Red Hat Openshift Container Platform+1

Nimrod Stoler

·

Published

2019-01-16

·

Updated

2023-10-25

·

CVE-2019-1003004

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.158 and earlier Jenkins LTS versions 2.150.1 and earlier Jenkins (affected versions not specified) in Redhat OpenShift Container Platform
Description The issue is related to an improper authorization vulnerability that allows attackers to extend the duration of active HTTP sessions indefinitely. This could enable a remote attacker to reuse login credentials or session identifiers for authentication, even if the user account has been deleted. The vulnerability is associated with the AuthenticationProcessingFilter2.java file in the core component of Jenkins.
Recommendations For Jenkins versions 2.158 and earlier, update to a version that includes the fix for this issue. For Jenkins LTS versions 2.150.1 and earlier, update to a newer LTS version that includes the fix. For Jenkins in Redhat OpenShift Container Platform, consider restricting access to the AuthenticationProcessingFilter2.java component until a patch is available. As a temporary workaround, consider disabling the reuse of session identifiers to minimize the risk of exploitation.

Fix

Improper Authorization

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BDU:2019-01048
CVE-2019-1003004
GHSA-8QXP-G8JV-P37X

Affected Products

Jenkins
Red Hat Openshift Container Platform