An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user account may have been deleted in the mean time.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Jenkins 2019 01 16 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest versionUpgrade Jenkins LTS to version 2.150.2Upgrade Jenkins to version 2.160 | Jan 23, 2019 | Jan 22, 2019 |
| Redhat Openshift | — | Upgrade atomic-openshift-metrics-serverUpgrade atomic-openshift-node-problem-detectorUpgrade atomic-openshiftUpgrade haproxyUpgrade atomic-openshift-web-consoleUpgrade openshift-enterprise-cluster-capacityUpgrade golang-github-prometheus-prometheusUpgrade jenkins-2-pluginsUpgrade openshift-ansibleUpgrade jenkinsUpgrade openshift-enterprise-autohealUpgrade atomic-openshift-dockerregistryUpgrade golang-github-prometheus-alertmanagerUpgrade atomic-openshift-deschedulerUpgrade atomic-openshift-service-idlerUpgrade golang-github-openshift-oauth-proxyUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshift-cluster-autoscalerUpgrade golang-github-prometheus-node_exporter | Apr 25, 2019 | Jan 16, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub