PT-2019-2981 · Cloudbees+1 · Jenkins

Published

2019-01-16

·

Updated

2023-10-25

·

CVE-2019-1003003

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.158 and earlier Jenkins LTS versions 2.150.1 and earlier
Description The issue is related to an improper authorization vulnerability in the TokenBasedRememberMeServices2.java component. This vulnerability allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, potentially leading to unauthorized access to protected information. The exploitation of this vulnerability could enable an attacker to persist access to temporarily compromised user accounts.
Recommendations For Jenkins versions 2.158 and earlier, consider disabling the TokenBasedRememberMeServices2.java component until a patch is available. For Jenkins LTS versions 2.150.1 and earlier, restrict access to the Remember Me functionality to minimize the risk of exploitation. As a temporary workaround, avoid using the Remember Me feature in the affected Jenkins versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

BDU:2019-02959
CVE-2019-1003003
GHSA-6RH5-23HX-J452

Affected Products

Jenkins