CVE-2019-1003049
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-613
- Affected
- jenkins/jenkins · redhat/openshift container platform · oracle/communications cloud native core automated test suite
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.securityfocus.com/bid/107901Broken Link
- https://access.redhat.com/errata/RHBA-2019:1605Third Party Advisory
- https://jenkins.io/security/advisory/2019-04-10/#SECURITY-1289Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/107901Broken Link
- https://access.redhat.com/errata/RHBA-2019:1605Third Party Advisory
- https://jenkins.io/security/advisory/2019-04-10/#SECURITY-1289Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.