8.1
CVSSv3

CVE-2019-1003049

Published: 10/04/2019 Updated: 25/10/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and previous versions and Jenkins LTS 2.164.1 and previous versions, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

redhat openshift container platform 3.11

oracle communications cloud native core automated test suite 1.9.0

Vendor Advisories

Impact: Moderate Public Date: 2019-04-10 CWE: CWE-592 Bugzilla: 1699701: CVE-2019-1003049 jenkins: Jenk ...
A security issue has been found in Jenkins before 2172, where the fix for SECURITY-901 in Jenkins 21502 and 2160 did not reject existing remoting-based CLI authentication caches This means that users who cached their CLI authentication before Jenkins was updated to 21502 and newer, or 2160 and newer, would remain authenticated ...