A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a new user account.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Jenkins 2018 10 10 | — | Upgrade Jenkins LTS to version 2.138.2Upgrade Jenkins to version 2.146Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest version | Jan 23, 2019 | Jan 9, 2019 |
| Redhat Openshift | — | Upgrade jenkins-2-pluginsUpgrade atomic-openshift-metrics-serverUpgrade golang-github-prometheus-alertmanagerUpgrade openshift-enterprise-cluster-capacityUpgrade atomic-openshift-node-problem-detectorUpgrade golang-github-prometheus-prometheusUpgrade atomic-openshift-cluster-autoscalerUpgrade openshift-ansibleUpgrade openshift-monitor-sample-appUpgrade jenkinsUpgrade openshift-monitor-project-lifecycleUpgrade atomic-openshiftUpgrade cri-oUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshift-deschedulerUpgrade golang-github-prometheus-node_exporterUpgrade kibanaUpgrade atomic-openshift-service-idlerUpgrade atomic-openshift-dockerregistryUpgrade golang-github-openshift-oauth-proxyUpgrade atomic-openshift-web-consoleUpgrade openshift-enterprise-autoheal | Apr 15, 2019 | Oct 10, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub