Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Jun 21, 2019 | Apr 10, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 10, 2019 |
| Jenkins 2019 04 10 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.164.2Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.172 | Apr 12, 2019 | Apr 10, 2019 |
| Redhat Openshift | — | Upgrade atomic-enterprise-service-catalogUpgrade golang-github-prometheus-node_exporterUpgrade golang-github-prometheus-prometheusUpgrade atomic-openshift-dockerregistryUpgrade atomic-openshift-deschedulerUpgrade atomic-openshift-cluster-autoscalerUpgrade jenkins-2-pluginsUpgrade cri-oUpgrade golang-github-prometheus-alertmanagerUpgrade openshift-enterprise-cluster-capacityUpgrade atomic-openshift-metrics-serverUpgrade atomic-openshift-service-idlerUpgrade openshift-enterprise-autohealUpgrade jenkinsUpgrade atomic-openshift-node-problem-detectorUpgrade golang-github-openshift-oauth-proxyUpgrade atomic-openshift-web-consoleUpgrade openshift-ansible | Jul 4, 2019 | Apr 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub