CVE-2018-1000409: Medium severity jenkins lts vulnerability
Published Jan 9, 2019
·Updated
A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a new user account.
Affected Software
4 affected componentsFixes available
maven/org.jenkins-ci.main:jenkins-core>=2.140<=2.145
2.146
maven/org.jenkins-ci.main:jenkins-core<=2.138.1
2.138.2
Jenkins Jenkins<=2.138.1
Jenkins Jenkins<=2.145
Event History
Jan 9, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
May 14, 2022
Advisory Published
01:04 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-1000409?
CVE-2018-1000409 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2018-1000409?
To fix CVE-2018-1000409, you should upgrade Jenkins to version 2.146 or higher.
3
Which versions of Jenkins are affected by CVE-2018-1000409?
Jenkins versions 2.145 and earlier, as well as LTS versions 2.138.1 and earlier, are affected by CVE-2018-1000409.
4
What type of vulnerability is CVE-2018-1000409?
CVE-2018-1000409 is a session fixation vulnerability.
5
What impact does CVE-2018-1000409 have on Jenkins?
CVE-2018-1000409 could allow an attacker to exploit existing sessions when a new user account is created.