CVE-2019-1003049 PUBLISHED CVSS 8.100000381469727 HIGH

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.

EPSS 0.47% · 64.6th percentile

Risk Scores

CVSS v3.1
8.100000381469727
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.47%
64.6th percentile

Affected Products

VendorProductVersions
jenkinsjenkins0, 0
redhatopenshift_container_platform3.11
Mavenorg.jenkins-ci.main:jenkins-core2.165, 0
Jenkins projectJenkins2.171 and earlier, LTS 2.164.1 and earlier
oraclecommunications_cloud_native_core_automated_test_suite1.9.0

Timeline

References

Open in Interactive Console →