CVE-2019-1003003: High severity jenkins lts vulnerability
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1003003?
CVE-2019-1003003 is classified as a medium severity vulnerability due to the potential for unauthorized access through crafted Remember Me cookies.
How do I fix CVE-2019-1003003?
To remediate CVE-2019-1003003, update Jenkins to version 2.159 or later, or 2.150.2 if using an earlier LTS version.
Which versions of Jenkins are affected by CVE-2019-1003003?
CVE-2019-1003003 affects Jenkins versions 2.158 and earlier, as well as LTS 2.150.1 and earlier.
What does CVE-2019-1003003 allow an attacker to do?
CVE-2019-1003003 allows attackers with Overall/RunScripts permission to create Remember Me cookies that do not expire, granting them persistent access.
Is CVE-2019-1003003 applicable to Red Hat OpenShift Container Platform?
Yes, CVE-2019-1003003 is applicable to the Red Hat OpenShift Container Platform version 3.11.