PT-2019-1544 · Red Hat+2 · Red Hat Openshift Container Platform+1
Nimrod Stoler
·
Published
2019-01-16
·
Updated
2023-10-25
·
CVE-2019-1003004
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.158 and earlier
Jenkins LTS versions 2.150.1 and earlier
Jenkins (affected versions not specified) in Redhat OpenShift Container Platform
Description
The issue is related to an improper authorization vulnerability that allows attackers to extend the duration of active HTTP sessions indefinitely. This could enable a remote attacker to reuse login credentials or session identifiers for authentication, even if the user account has been deleted. The vulnerability is associated with the
AuthenticationProcessingFilter2.java file in the core component of Jenkins.Recommendations
For Jenkins versions 2.158 and earlier, update to a version that includes the fix for this issue.
For Jenkins LTS versions 2.150.1 and earlier, update to a newer LTS version that includes the fix.
For Jenkins in Redhat OpenShift Container Platform, consider restricting access to the
AuthenticationProcessingFilter2.java component until a patch is available.
As a temporary workaround, consider disabling the reuse of session identifiers to minimize the risk of exploitation.Fix
Improper Authorization
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jenkins
Red Hat Openshift Container Platform