CVE-2019-1003049: High severity jenkins lts vulnerability
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-1003049?
CVE-2019-1003049 is a vulnerability that allows users who cached their CLI authentication before Jenkins was updated to remain authenticated in certain versions of Jenkins.
Which versions of Jenkins are affected by CVE-2019-1003049?
Jenkins versions 2.164.1 and earlier, as well as Jenkins LTS 2.164.1 and earlier, are affected by CVE-2019-1003049.
What is the severity of CVE-2019-1003049?
CVE-2019-1003049 has a severity rating of 8.1 (high).
How can I fix CVE-2019-1003049?
To fix CVE-2019-1003049, users should update Jenkins to version 2.150.2 or newer, or version 2.160 or newer.
Where can I find more information about CVE-2019-1003049?
More information about CVE-2019-1003049 can be found at the following references: http://www.securityfocus.com/bid/107901, https://access.redhat.com/errata/RHBA-2019:1605, https://jenkins.io/security/advisory/2019-04-10/#SECURITY-1289